From 2fccc2a2d8ccc56d736b235fc07d8d41f21fa65b Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 05:13:26 +0000 Subject: [PATCH 01/27] docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2 (kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing. Sibling #1959 closed as already-retired by PR #1272. Co-Authored-By: Claude Opus 4.7 (1M context) --- ...e-source-span-file-participation-worker.md | 66 +++++++++++++++++++ 1 file changed, 66 insertions(+) create mode 100644 docs/briefs/r3-substrate-bridge-source-span-file-participation-worker.md diff --git a/docs/briefs/r3-substrate-bridge-source-span-file-participation-worker.md b/docs/briefs/r3-substrate-bridge-source-span-file-participation-worker.md new file mode 100644 index 00000000000..9811b03c9c9 --- /dev/null +++ b/docs/briefs/r3-substrate-bridge-source-span-file-participation-worker.md @@ -0,0 +1,66 @@ +# Worker brief — Substrate bridge: `SourceSpan.file` participation checks (1 of 2) + +**Sub-issue**: gunbc#1958 (parented under #1939 Substrate Mgr lane). +**Sibling**: gunbc#1959 closed 2026-05-07 — already retired by PR #1272. +**Authority anchors**: `docs/briefs/bridge-retirement-audit-sourcespan-family.md` (19-row enumeration); `docs/r3-program-plan.md:353` Substrate-owned scope clarification; `src/v3/std/bridge_ledger.dag` row `bridge_source_span_file_participation_retired` (status=`Proposed`). + +## Scope (Substrate-owned, narrow) + +Per **r3-program-plan.md §5 line 353** Y4 scope-clarification: + +> Substrate-owned: `SourceSpan.file` participation checks (**hand-Rust audit sites only** — +> `bootstrap.rs:519` doc-comment + `:137` / `:287` / `:309` hardcoded path strings; +> codegen-emitted `SourceSpan::new(...)` offsets in `bootstrap_generated.rs` are a +> separate generated-file bridge shape, **NOT counted as Substrate-owned manual hand-Rust**). + +This brief targets **bootstrap.rs hand-Rust sites only**. The 19-row audit packet's broader rows (`lens_apply.rs`, `test_runner.rs`, `dag.rs::declaration_by_name` rank tables, etc.) are owned by Verification / PB per the audit-packet leaf-first schedule — **not in scope here**. + +## Concrete anchor sites in `bootstrap.rs` at HEAD + +| Anchor | Site | Bridge shape | +|---|---|---| +| 1 | `:125-129` Bool resolver | `d.span.file == BOOL_TYPES_FILE` — identity-by-path-string (audit row #2) | +| 2 | `:138` | `SourceSpan::new(BOOL_TYPES_FILE, 0, 0)` — diagnostic span manufactured from path constant (audit row #2) | +| 3 | `:285` | `BootstrapAuthorityKey::new(PIPELINE_AUTHORITY_FILE)` — string-keyed authority (audit row #6) | +| 4 | `:288` | `SourceSpan::new(PIPELINE_AUTHORITY_FILE, 0, 0)` — diagnostic span (audit row #6) | +| 5 | `:309` | `SourceSpan::new("", 0, 0)` — **test fixture, NOT a bridge** (synthetic span; OK to keep) | +| 6 | `:519` doc-comment | references `SourceSpan.file` for prose only (no runtime check; doc-update on retirement) | + +Authority constants: `BOOL_TYPES_FILE` (`dsl/std/types.dag`), `PIPELINE_AUTHORITY_FILE` (`src/v3/compiler/src/pipeline.dag` per `pipeline_authority.rs`). + +## Retirement shape (per audit-packet rows #2 + #6) + +**Row #2 (kernel Bool patch)** — replace identity-by-path with structural lookup: +- Use `Dag::declaration_by_name("Bool")` already-canonical lookup; gate by **bootstrap-module witness** (declaration's owning module-id rather than `span.file` string match). +- Diagnostic span: synthesize from `BootstrapAuthorityKey` rather than `SourceSpan::new(BOOL_TYPES_FILE, 0, 0)` — the `BootstrapAuthorityKey::new(...)` wrapper already exists at `:125`, and `DiagnosticAttribution::BootstrapAuthority` (per `:519` doc-comment) is the steady-state attribution surface (PB row 82). +- **Prerequisite**: `dsl/std/types.dag` ↔ `src/v3/std/types.dag` duplicate-module convergence per ROADMAP T-P0 must NOT regress; if both hold a `Bool`, `declaration_by_name` rank still applies (audit row #14 — root blocker, **out-of-scope here**). + +**Row #6 (pipeline authority)** — replace `PIPELINE_AUTHORITY_FILE` guards: +- `report_pipeline_authority_error` (`:283-292`) — drop the path-string from both `BootstrapAuthorityKey` and `SourceSpan::new`. Replace with a **`BootstrapAuthority::Pipeline` typed key** (extend the enum if needed); diagnostic span sourced from the offending stage binding's actual `SourceSpan`, not a manufactured `(file, 0, 0)`. +- Coordinate with PB-owned `bridge_include_str_side_channels_retired` (audit row #6 sibling) — `pipeline_authority.rs::ordered_pipeline_stages` already reads `PipelineStageBinding` structurally; the bridge is ONLY in the diagnostic-span manufacturing path. + +## Acceptance + +1. `bootstrap.rs` no longer references `BOOL_TYPES_FILE` or `PIPELINE_AUTHORITY_FILE` outside doc-comments. +2. The two diagnostic paths (kernel Bool not-found, pipeline-authority error) carry typed `DiagnosticAttribution::BootstrapAuthority` with the appropriate `BootstrapAuthorityKey` variant — verified by `kernel_bool_path_a_diagnostic_carries_bootstrap_authority_attribution` (already exists at `:519+`) extended for the pipeline path if not present. +3. `src/v3/std/bridge_ledger.dag` row `bridge_source_span_file_participation_retired` advances `Proposed` → `Retired` for the Substrate-owned scope; ledger receipt mentions PR # + scope-narrowing (audit rows #2 + #6 only; rows #1, #3-5, #7-19 remain under their owners). +4. `dag.rs::bridge_source_span_file_participation_retired` ratchet test (if not already authored — Verification-owned per `r3-v-bridge-ratchet-test-design.md`) passes; if test doesn't exist yet, surface to Verification Mgr (#1940) for ratchet authoring as cross-Mgr handoff. +5. Bootstrap regen: `cargo test -p v3-compiler bootstrap_regen_fresh -- --ignored` clean (path-string deletion must not perturb regen byte-snapshot). +6. Full suite: `cargo test --workspace --exclude v2-compiler-tests` green; `cargo clippy --all-targets -- -D warnings` clean. + +## STOP / PING criteria + +- **STOP** if removing `d.span.file == BOOL_TYPES_FILE` (anchor #1) causes `declaration_by_name("Bool")` to resolve to a different declaration (rank-table ambiguity from duplicate `Bool` in `src/v3/std/types.dag` vs `dsl/std/types.dag`). This is audit row #14 root-blocker territory — surface to Mgr; do NOT delete the rank table to "fix it". +- **STOP** if `BootstrapAuthority` enum doesn't have a `Pipeline` variant and adding one cascades into emit/diagnostic surfaces beyond bootstrap.rs. Surface scope-creep to Mgr. +- **PING** Verification Mgr (#1940 / `witty-swift-269` if active) when this lands so they can advance the ledger-zero audit (`docs/briefs/r3-v-bridge-retirement-ledger-zero-audit.md` row 1). + +## Cross-Mgr handoff + +- **PB Mgr**: audit row #6's sibling (`bridge_include_str_side_channels_retired` for `pipeline_authority.rs` compile-body drift) is PB-owned; this Substrate slice does NOT touch the include_str path, only the diagnostic-span path. No cross-PR coordination needed unless audit row interpretation drifts at execution time. +- **Verification Mgr**: ratchet authoring + ledger-zero audit advancement. + +## Worker disposition + +Single PR (~150-300 LoC delta + test). Use standing-authority merge per Director directive 2026-05-07 once CLEAN + green CI + reviewer comments without BLOCKING + sitting >30min. + +— Authored by warm-wolf-698 (Substrate Mgr) 2026-05-07 per Director endorsement at gunbc#828 #issuecomment-4394293399. From 8c5f054430ffcc5aa5d9cbe9123a492cc55c70ec Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 05:24:11 +0000 Subject: [PATCH 02/27] docs(briefs): S5 Variant-aware projection carrier canvas (#1947) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag / β Declaration variant_projection_metadata / γ free-standing CoproductProjection) for Director ratification before worker brief authoring. Mgr-tier recommendation = γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge). Co-Authored-By: Claude Opus 4.7 (1M context) --- ...variant-aware-projection-carrier-canvas.md | 79 +++++++++++++++++++ 1 file changed, 79 insertions(+) create mode 100644 docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md diff --git a/docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md b/docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md new file mode 100644 index 00000000000..3cf0e4bc62e --- /dev/null +++ b/docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md @@ -0,0 +1,79 @@ +# Canvas — Substrate S5 Variant-aware projection metadata carrier + +**Sub-issue**: gunbc#1947 (parented under #1939 Substrate Mgr lane). +**Authority**: `docs/r3-design-schedule-2026-05-06.md` §S5 (lines 101-106); `docs/r3-program-plan.md:979` Q-Anthropic-Variant-Aware (RATIFIED-by-default — all 3 paydowns); Substrate canvas C1. +**Status**: **canvas — Director-tier ratification needed on carrier shape before worker brief authoring**. + +## Scope + +Typed REST response projection carrier for **coproduct response bodies** — the substrate fact that lets a typed REST response `from`-path resolver dispatch on a sum-type response variant rather than collapsing into untyped JSON. + +Closure: §1.8 gates #29-#30 (T-Anthropic-Wire 2 gates); unblocks #1702 Anthropic re-dispatch + 3 follow-up paydown PRs (Anthropic Messages 200 residual + 2 sibling coproduct slices already-briefed at `r3-coproduct-{2,3}-*.md`). + +## Why a canvas not a worker brief + +Carrier shape is a **substrate-fact-introduction (P1 procedure)** with non-trivial design space. Authoring a worker brief without Director ratification of shape risks rework. Surfacing 3 carrier-shape options for ratification. + +## Carrier-shape options + +### Option α — Variant-tag projection on `RestResponseProjection` + +Extend the existing `RestResponseProjection` carrier (if extant; else introduce alongside `CoproductWireContract` at `dsl/extdeps/llm/anthropic.dag:20-30` precedent) with a per-variant projection field: + +```dag +type RestResponseProjection + = { request_path: String + , response_variant_tag: String + , response_body_field: List + } +``` + +Indexed by `(method, response_variant_tag)`. Resolver picks the matching projection by parsing the response wire-tag (e.g., `type` discriminator in Anthropic's content-block coproducts) and dispatching to the variant's projection. + +**Pro**: minimal new substrate; reuses `FieldProjection` shape; aligns with `CoproductWireContract::InternallyTaggedObject` (which Anthropic uses already at `:20-30`). +**Con**: tag-string IS a bridge — the rank-table risk of audit-row #14 family. Acceptable because tag strings are wire-protocol identity (not internal compiler identity), but worth flagging. + +### Option β — Sum-type metadata on `Declaration` + +Generalize: every coproduct `Declaration` carries optional `variant_projection_metadata: Option>`. The resolver finds the declaration via existing identity surface (declaration_by_name or DeclarationRef) and picks variant by structural variant-id, not wire string. + +**Pro**: structural — no string bridge. Reuses sum-type variant identity already in `Declaration` (TypeBody::Sum variant constructors per VariantConstruct lowerer at memory/MEMORY.md:201). +**Con**: heavier substrate change; couples REST-response-specific concern to general `Declaration`. May leak to other coproduct uses without need. + +### Option γ — Free-standing `CoproductProjection` carrier + +New top-level carrier in `dsl/extdeps/llm/wire_contracts.dag` (or similar): + +```dag +type CoproductProjection + = { coproduct_decl: DeclarationRef + , wire_tag_field: String // e.g., "type" + , variant_projections: Map + } +``` + +Lookup: `coproduct_projection_for(decl: DeclarationRef) -> CoproductProjection`. Wire-tag string lives in projection data, not in identity dispatch. + +**Pro**: localizes the wire-coproduct-dispatch concern to one named carrier; avoids polluting `Declaration`. DeclarationRef-keyed (not span.file-keyed) — clean of audit-row-#14 concerns. +**Con**: new carrier type; some duplication if `RestResponseProjection` already carries a similar shape. + +## Director ratification ask + +1. **Pick α / β / γ** (or surface a fourth option). Provisional Mgr-tier recommendation: **γ** — DeclarationRef-keyed, localized to wire-protocol concern, doesn't leak into `Declaration` general surface, avoids the tag-string-as-identity concern of α. +2. Confirm scope: carrier-only at S5, or carrier + 1 of 3 paydowns bundled? Current default per Q-Anthropic-Variant-Aware = carrier + ALL 3 paydowns separately (already briefed). Confirm S5 dispatch is **carrier-only**; the 3 paydowns dispatch in their own briefs. + +## On ratification — worker brief scope + +Will author execution brief covering: +- New carrier definition in chosen location (`dsl/extdeps/llm/wire_contracts.dag` per γ, or alternate per ratification) +- Indexing API (`coproduct_projection_for(decl) -> CoproductProjection` or analog) +- Resolver wiring point in `from`-path resolution (typed REST response projection consumer) +- Acceptance: §1.8 gates #29-#30 advance from declared → carrier-landed; #1702 branch unparks +- Bootstrap regen + clippy + workspace tests green +- Cross-Mgr handoff: 3 coproduct paydown briefs already authored (`r3-coproduct-{1,2,3}-*-worker.md`) ready to dispatch in their own PRs post-S5 land + +## Worker pin candidates (post-ratification) + +valiant-ibex-312 (recently freed post-#1933 IntPlatform/UIntPlatform land — substrate-fact-introduction precedent owner) OR smart-ram-167. Final pin at dispatch. + +— Authored by warm-wolf-698 (Substrate Mgr) 2026-05-07 per Director endorsement at gunbc#828 #issuecomment-4394293399 of authoring next 2-3 unbriefed items. From d82695049748bfdbbd8539ea0cc9adcb3026e7d3 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 05:25:31 +0000 Subject: [PATCH 03/27] =?UTF-8?q?docs(briefs):=20SourceSpan.file=20brief?= =?UTF-8?q?=20=E2=80=94=20same-slice=20prerequisite=20+=20section=20anchor?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Director calibration (gunbc#2079 #issuecomment-...): 1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4 to upfront same-slice BLOCKING prerequisite gate (per feedback_same_slice_dissolution_discipline). 2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification` section anchor (per feedback_section_anchors_over_line_numbers). Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to). Co-Authored-By: Claude Opus 4.7 (1M context) --- ...ate-bridge-source-span-file-participation-worker.md | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/docs/briefs/r3-substrate-bridge-source-span-file-participation-worker.md b/docs/briefs/r3-substrate-bridge-source-span-file-participation-worker.md index 9811b03c9c9..738906aef43 100644 --- a/docs/briefs/r3-substrate-bridge-source-span-file-participation-worker.md +++ b/docs/briefs/r3-substrate-bridge-source-span-file-participation-worker.md @@ -2,11 +2,15 @@ **Sub-issue**: gunbc#1958 (parented under #1939 Substrate Mgr lane). **Sibling**: gunbc#1959 closed 2026-05-07 — already retired by PR #1272. -**Authority anchors**: `docs/briefs/bridge-retirement-audit-sourcespan-family.md` (19-row enumeration); `docs/r3-program-plan.md:353` Substrate-owned scope clarification; `src/v3/std/bridge_ledger.dag` row `bridge_source_span_file_participation_retired` (status=`Proposed`). +**Authority anchors**: `docs/briefs/bridge-retirement-audit-sourcespan-family.md` (19-row enumeration); `docs/r3-program-plan.md` **§5 Y4 scope-clarification** (current line 353 anchor — verify section heading at HEAD); `src/v3/std/bridge_ledger.dag` row `bridge_source_span_file_participation_retired` (status=`Proposed`). + +## Cross-Mgr prerequisite (same-slice blocking gate) + +`bridge_source_span_file_participation_retired` ratchet test (Verification-owned per `r3-v-bridge-ratchet-test-design.md`). If not yet authored at HEAD when worker starts, surface to Verification Mgr (#2075 / lane #1940) for ratchet authoring **AS A SAME-SLICE BLOCKING PREREQUISITE** — Substrate worker's PR does NOT merge until Verification's ratchet is in place. Do NOT proceed under "surface as follow-up" framing; the dissolution trigger (ratchet passing) IS a same-slice acceptance criterion. Sequence: Verification ratchet PR lands first → this Substrate retirement PR consumes it. ## Scope (Substrate-owned, narrow) -Per **r3-program-plan.md §5 line 353** Y4 scope-clarification: +Per **r3-program-plan.md §5 Y4 scope-clarification**: > Substrate-owned: `SourceSpan.file` participation checks (**hand-Rust audit sites only** — > `bootstrap.rs:519` doc-comment + `:137` / `:287` / `:309` hardcoded path strings; @@ -44,7 +48,7 @@ Authority constants: `BOOL_TYPES_FILE` (`dsl/std/types.dag`), `PIPELINE_AUTHORIT 1. `bootstrap.rs` no longer references `BOOL_TYPES_FILE` or `PIPELINE_AUTHORITY_FILE` outside doc-comments. 2. The two diagnostic paths (kernel Bool not-found, pipeline-authority error) carry typed `DiagnosticAttribution::BootstrapAuthority` with the appropriate `BootstrapAuthorityKey` variant — verified by `kernel_bool_path_a_diagnostic_carries_bootstrap_authority_attribution` (already exists at `:519+`) extended for the pipeline path if not present. 3. `src/v3/std/bridge_ledger.dag` row `bridge_source_span_file_participation_retired` advances `Proposed` → `Retired` for the Substrate-owned scope; ledger receipt mentions PR # + scope-narrowing (audit rows #2 + #6 only; rows #1, #3-5, #7-19 remain under their owners). -4. `dag.rs::bridge_source_span_file_participation_retired` ratchet test (if not already authored — Verification-owned per `r3-v-bridge-ratchet-test-design.md`) passes; if test doesn't exist yet, surface to Verification Mgr (#1940) for ratchet authoring as cross-Mgr handoff. +4. `dag.rs::bridge_source_span_file_participation_retired` ratchet test passes (authored by Verification per the **Cross-Mgr prerequisite** gate above; confirmed-present at HEAD before this PR merges). 5. Bootstrap regen: `cargo test -p v3-compiler bootstrap_regen_fresh -- --ignored` clean (path-string deletion must not perturb regen byte-snapshot). 6. Full suite: `cargo test --workspace --exclude v2-compiler-tests` green; `cargo clippy --all-targets -- -D warnings` clean. From f26a582bdf8c275fb4a74e8a4dc5a9d69f659fee Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 05:28:12 +0000 Subject: [PATCH 04/27] =?UTF-8?q?docs(briefs):=20SourceSpan.file=20brief?= =?UTF-8?q?=20=E2=80=94=20umbrella=20stays=20Open=20per=20P2=20ledger=20di?= =?UTF-8?q?scipline?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired is an Open umbrella whose green predicate is "no production code path consults SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139). Changes: - Add Ledger-discipline preamble: umbrella row stays Open; receipt updates audit-packet enumeration, NOT bridge_ledger.dag. - Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6 retired in the audit packet only. - Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115 + bridge_ledger.dag:125-129 line refs. - Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone; Verification's ledger-zero audit progress field is post-merge tracking, not a same-slice pre-merge blocker. Reconciles with BLOCKING finding (Director calibration #1 assumed umbrella ratchet could flip on partial retirement, which r3-structure.md:115 forbids). Co-Authored-By: Claude Opus 4.7 (1M context) --- ...bridge-source-span-file-participation-worker.md | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) diff --git a/docs/briefs/r3-substrate-bridge-source-span-file-participation-worker.md b/docs/briefs/r3-substrate-bridge-source-span-file-participation-worker.md index 738906aef43..2635216a14c 100644 --- a/docs/briefs/r3-substrate-bridge-source-span-file-participation-worker.md +++ b/docs/briefs/r3-substrate-bridge-source-span-file-participation-worker.md @@ -2,11 +2,17 @@ **Sub-issue**: gunbc#1958 (parented under #1939 Substrate Mgr lane). **Sibling**: gunbc#1959 closed 2026-05-07 — already retired by PR #1272. -**Authority anchors**: `docs/briefs/bridge-retirement-audit-sourcespan-family.md` (19-row enumeration); `docs/r3-program-plan.md` **§5 Y4 scope-clarification** (current line 353 anchor — verify section heading at HEAD); `src/v3/std/bridge_ledger.dag` row `bridge_source_span_file_participation_retired` (status=`Proposed`). +**Authority anchors**: `docs/briefs/bridge-retirement-audit-sourcespan-family.md` (19-row enumeration); `docs/r3-program-plan.md` **§5 Y4 scope-clarification** (current line 353 anchor — verify section heading at HEAD); `src/v3/std/bridge_ledger.dag:125-129` row `bridge_source_span_file_participation_retired` (status=`Open`); `docs/r3-structure.md:115` umbrella-gate framing. -## Cross-Mgr prerequisite (same-slice blocking gate) +## Ledger-discipline preamble (P2 single-authority) -`bridge_source_span_file_participation_retired` ratchet test (Verification-owned per `r3-v-bridge-ratchet-test-design.md`). If not yet authored at HEAD when worker starts, surface to Verification Mgr (#2075 / lane #1940) for ratchet authoring **AS A SAME-SLICE BLOCKING PREREQUISITE** — Substrate worker's PR does NOT merge until Verification's ratchet is in place. Do NOT proceed under "surface as follow-up" framing; the dissolution trigger (ratchet passing) IS a same-slice acceptance criterion. Sequence: Verification ratchet PR lands first → this Substrate retirement PR consumes it. +**The umbrella ledger row stays `Open`.** Per `docs/r3-structure.md:115` and Director acceptance #1130 / dispatch #1139 (2026-04-29): partial string-check retirement was **explicitly rejected** because parallel participation rules would remain. The umbrella's green predicate is *"no production code path consults `SourceSpan.file` for participation/inclusion logic"* — all-or-nothing. Production inclusion sites enumerated at `r3-structure.md:115` (in `lens_apply.rs` / `lower.rs` / `emit.rs`) are NOT in this Substrate slice's scope; they retire under their owners. + +This PR's outcome = **retire the bootstrap.rs subset of audit-packet rows #2 + #6 only**. Receipt = update the audit-packet enumeration table at `docs/briefs/bridge-retirement-audit-sourcespan-family.md` to mark rows #2 + #6 retired with the PR # citation. **Do NOT mutate `bridge_ledger.dag`** for this PR — the umbrella row stays `Open` until ALL production sites in the audit packet (rows #1, #3-19 minus test-only / out-of-family) are retired across owner-scoped PRs. + +## Cross-Mgr coordination (informational; NOT a same-slice blocker) + +The umbrella `bridge_source_span_file_participation_retired` ratchet (Verification's `bridge_retirement_ledger_zero` audit per `r3-v-bridge-retirement-ledger-zero-audit.md`) cannot flip green on this PR alone — production sites in `lens_apply.rs` / `lower.rs` / `emit.rs` (per `r3-structure.md:115`) remain post-this-PR. Verification's ledger-zero audit advances when ALL audit-packet rows retire; this PR contributes rows #2 + #6 progress only. No same-slice ratchet-test gate applies to this PR; ping Verification Mgr (#2075 / lane #1940) on merge so they can update the ledger-zero audit progress field, but their action is **post-merge tracking**, not a pre-merge blocker. ## Scope (Substrate-owned, narrow) @@ -47,7 +53,7 @@ Authority constants: `BOOL_TYPES_FILE` (`dsl/std/types.dag`), `PIPELINE_AUTHORIT 1. `bootstrap.rs` no longer references `BOOL_TYPES_FILE` or `PIPELINE_AUTHORITY_FILE` outside doc-comments. 2. The two diagnostic paths (kernel Bool not-found, pipeline-authority error) carry typed `DiagnosticAttribution::BootstrapAuthority` with the appropriate `BootstrapAuthorityKey` variant — verified by `kernel_bool_path_a_diagnostic_carries_bootstrap_authority_attribution` (already exists at `:519+`) extended for the pipeline path if not present. -3. `src/v3/std/bridge_ledger.dag` row `bridge_source_span_file_participation_retired` advances `Proposed` → `Retired` for the Substrate-owned scope; ledger receipt mentions PR # + scope-narrowing (audit rows #2 + #6 only; rows #1, #3-5, #7-19 remain under their owners). +3. **Ledger discipline (per Ledger-discipline preamble):** `src/v3/std/bridge_ledger.dag` row stays `Open` — do NOT mutate. Audit-packet table at `docs/briefs/bridge-retirement-audit-sourcespan-family.md` updated to mark **rows #2 + #6 only** retired with this PR's # citation (rows #1, #3-5, #7-19 remain under their owners; umbrella row advances to `Retired` only when ALL production sites are retired across owner-scoped PRs). 4. `dag.rs::bridge_source_span_file_participation_retired` ratchet test passes (authored by Verification per the **Cross-Mgr prerequisite** gate above; confirmed-present at HEAD before this PR merges). 5. Bootstrap regen: `cargo test -p v3-compiler bootstrap_regen_fresh -- --ignored` clean (path-string deletion must not perturb regen byte-snapshot). 6. Full suite: `cargo test --workspace --exclude v2-compiler-tests` green; `cargo clippy --all-targets -- -D warnings` clean. From beabfa41f91053fcef8f830aaf08eb94415417fd Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 05:36:43 +0000 Subject: [PATCH 05/27] =?UTF-8?q?docs(briefs):=20S5=20CoproductProjection?= =?UTF-8?q?=20worker=20brief=20=E2=80=94=20=CE=B3=20ratified=20(#1947)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Director ratification of option γ at gunbc#828 #issuecomment-4394369848. Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed, typed WireTagValue leaf, 4 same-slice acceptance gates. Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier landing (heads-up, not blocker). Co-Authored-By: Claude Opus 4.7 (1M context) --- ...-s5-coproduct-projection-carrier-worker.md | 67 +++++++++++++++++++ 1 file changed, 67 insertions(+) create mode 100644 docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md diff --git a/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md b/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md new file mode 100644 index 00000000000..eed5d47105e --- /dev/null +++ b/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md @@ -0,0 +1,67 @@ +# Worker brief — Substrate S5 `CoproductProjection` carrier (γ) + +**Sub-issue**: gunbc#1947 (parented under #1939 Substrate Mgr lane). +**Authority**: Director ratification of **option γ** at gunbc#828 #issuecomment-4394369848 (2026-05-07); supersedes the canvas at `docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md` (canvas may be deleted after this brief lands). +**Closure predicate**: §1.8 gates #29-#30 (T-Anthropic-Wire 2 gates); unblocks Anthropic #1702 re-dispatch + 3 already-briefed coproduct paydowns (`r3-coproduct-{1,2,3}-*-worker.md`). + +## Scope + +Substrate-fact-introduction (P1 procedure): typed REST response projection carrier for coproduct response bodies. Free-standing carrier keyed by `DeclarationRef`; wire-tag in DATA, not identity. + +## Carrier shape (binding per Director) + +**Location**: `src/v3/std/coproduct_projection.dag` (verify-via-grep at HEAD that this file does not yet exist; if a near-neighbor already hosts compatible projection types, fold in cleanly). **NOT** `dsl/std/` — this is compiler-internal projection substrate, not user-facing language vocabulary. Contrast: `dsl/std/serialization.dag::CoproductWireContract` lives in `dsl/std/` because users declare wire contracts; `CoproductProjection` is for internal projection-resolver dispatch. + +**Initial shape** (refine in implementation as ergonomics demand): + +```dag +type CoproductProjection { + declaration: DeclarationRef + variant_field_projections: Map + wire_tag_field: FieldRef // which field carries the wire-tag discriminator + wire_tag_values: Map +} +``` + +`WireTagValue` MUST be a typed leaf (sum type or named record), **not** `String`. If Anthropic + REST both serialize as string at the wire boundary, encode the typed-on-our-side / serialized-at-emit pattern: `WireTagValue` stays typed in substrate; serialization adapter handles `String <-> WireTagValue` at the wire boundary. + +### Substrate observations the worker must surface (do not silently work around) + +1. **`DeclarationRef = String` alias at `dsl/std/serialization.dag:16`** — Director's ratification framing emphasizes "typed key, not string identity (avoids audit row #14 collision)". The current `DeclarationRef` IS a String alias. If `CoproductProjection.declaration: DeclarationRef` is to be a real typed key, either (a) `DeclarationRef` itself must promote to a structural typed shape (e.g., `(module: ModuleId, name: DeclarationName)` record) — substantial substrate change, surface as scope question; OR (b) accept the alias as a soft-typed nominal handle for this carrier slice and note the future-promotion debt. **STOP-and-PING the Mgr** before proceeding; don't choose silently. + +2. **`FieldRef` does not exist at HEAD** as a standalone type (only `InputFieldRef` mentioned in `services.dag:34`). The brief asks for a typed `FieldRef` carrier. Either reuse `InputFieldRef` if its semantics generalize, or introduce `FieldRef` alongside `CoproductProjection`. Choose pragmatically; don't introduce a parallel-authority second `FieldRef`. + +3. **`InternallyTaggedObject.tag_field: String`** at `dsl/std/serialization.dag:49` already uses a String tag-field. The new typed `FieldRef` shape will create a typed/string asymmetry between the two carriers. Either (a) `CoproductProjection.wire_tag_field` is `FieldRef` and the asymmetry is documented as tracked debt (eventually `InternallyTaggedObject` migrates), or (b) accept `String` for `wire_tag_field` to match. Director's binding constraint #2 is explicit: typed leaf `WireTagValue`; the `wire_tag_field` field shape is less hard-binding. Recommend (a) — typed introduction here, debt note for `InternallyTaggedObject` migration. + +## Acceptance gates (same-slice, all must pass) + +1. **Carrier landed** in `src/v3/std/coproduct_projection.dag` (or chosen location post-grep) with the shape above (modulo STOP-resolved decisions on items 1-3). +2. **Anthropic #1702 re-dispatch wires through `CoproductProjection`** — NOT through any `response_variant_tag: String` shim. The `from`-path resolver consumes `CoproductProjection` to dispatch on coproduct response variants. (Anthropic #1702 work is preserved on branch `codex/cc1-target-integer-structural-fold` per Grounding G5; merge unblocks on this carrier.) +3. **At least one of the 3 already-briefed coproduct paydowns consumes `CoproductProjection`** — proof of multi-consumer composability. Refutes "carrier with single consumer is just an interface" anti-pattern. Worker picks the easiest of `r3-coproduct-{1,2,3}-*-worker.md` to thread through; documents which one in the PR description. The other two paydowns dispatch in their own PRs after. +4. **No `Option<>` wrapping on `Declaration`** — verify via grep at acceptance time that no `variant_projection_metadata: Option<...>` field was added to `Declaration` (per Director's β-rejection rationale; `feedback_node_not_god_struct` analog). +5. Bootstrap regen: `cargo test -p v3-compiler bootstrap_regen_fresh -- --ignored` clean (carrier is added; no existing surface should perturb). +6. Full suite: `cargo test --workspace --exclude v2-compiler-tests` green; `cargo clippy --all-targets -- -D warnings` clean. + +## STOP / PING criteria + +- **STOP** before proceeding if: + - `DeclarationRef` typed-promotion question (substrate observation #1) cannot be answered locally — surface to Mgr (warm-wolf-698 / inbox #2068). + - `FieldRef` introduction cascades into emit/typecheck surfaces beyond `coproduct_projection.dag` and the chosen consumer paydown — surface scope-creep. + - At carrier-shape implementation time, `WireTagValue` typed-leaf shape forces a String<->typed adapter that has nontrivial bootstrap-regen impact — surface. +- **PING** PB Mgr (#2074 / `warm-dove-618`) at carrier-landing time per Director's cross-Mgr coordination note: PB owns `T-LensProducer-Retirement` which may consume similar projection shapes. They may have downstream needs constraining the carrier. **This is a heads-up, not a same-slice blocker** — PB's input refines future iterations. + +## Cross-Mgr coordination + +- **Anthropic #1702 (Grounding G5)**: re-dispatch unblocks at carrier-landing. Heads-up to Grounding Mgr (#1944 / `clever-otter-128` if active) at PR-open time. +- **PB Mgr (#2074)**: see PING above. +- **Verification Mgr (#2075)**: ratchet authoring for `bridge_*_carrier_landed`-shaped gates is Verification's standing concern; no specific same-slice handoff expected here unless ledger row needs to advance (which on a carrier-introduction is normal — §1.8 gates #29-#30 advance to `CONSUMER_LANDED` per closure predicate). + +## Worker pin (Mgr disposition) + +**valiant-ibex-312** preferred — substrate-fact-introduction precedent owner (delivered IntPlatform/UIntPlatform via PR #1933). Fallback: smart-ram-167. Final pin at dispatch. + +## Auto-spawn caveat + +Per Director's note 2026-05-07: worker auto-spawn from Mgr-context is currently bug-affected (PM investigating); manual dispatch via PR creation under Mgr session branch is acceptable for low-risk shapes but L+ workers should hold until fix. This carrier is L-sized (substrate-fact-introduction + 1 multi-consumer paydown thread-through); recommend **HOLD dispatch until auto-spawn fix lands** or operator-directed manual route. Brief is dispatch-ready regardless. + +— Authored by warm-wolf-698 (Substrate Mgr) 2026-05-07 per Director γ-ratification at gunbc#828 #issuecomment-4394369848. From 925a412b0de5ed1209eb48d7336327effc5bdc8a Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 05:38:41 +0000 Subject: [PATCH 06/27] =?UTF-8?q?docs(briefs):=20SourceSpan.file=20brief?= =?UTF-8?q?=20=E2=80=94=20resolve=20Acceptance=20#4=20/=20Cross-Mgr=20cont?= =?UTF-8?q?radiction?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4 ("ratchet test passes ... confirmed-present at HEAD before merge") contradicting the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge tracking only"). Both said different things about whether the umbrella ratchet is a pre-merge blocker. Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet pre-merge gate" — worker does NOT wait for Verification ratchet authoring; acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr handoff also updated to remove "ratchet authoring" from Verification's same-slice duties. Co-Authored-By: Claude Opus 4.7 (1M context) --- ...-substrate-bridge-source-span-file-participation-worker.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/briefs/r3-substrate-bridge-source-span-file-participation-worker.md b/docs/briefs/r3-substrate-bridge-source-span-file-participation-worker.md index 2635216a14c..b4b05d79f6c 100644 --- a/docs/briefs/r3-substrate-bridge-source-span-file-participation-worker.md +++ b/docs/briefs/r3-substrate-bridge-source-span-file-participation-worker.md @@ -54,7 +54,7 @@ Authority constants: `BOOL_TYPES_FILE` (`dsl/std/types.dag`), `PIPELINE_AUTHORIT 1. `bootstrap.rs` no longer references `BOOL_TYPES_FILE` or `PIPELINE_AUTHORITY_FILE` outside doc-comments. 2. The two diagnostic paths (kernel Bool not-found, pipeline-authority error) carry typed `DiagnosticAttribution::BootstrapAuthority` with the appropriate `BootstrapAuthorityKey` variant — verified by `kernel_bool_path_a_diagnostic_carries_bootstrap_authority_attribution` (already exists at `:519+`) extended for the pipeline path if not present. 3. **Ledger discipline (per Ledger-discipline preamble):** `src/v3/std/bridge_ledger.dag` row stays `Open` — do NOT mutate. Audit-packet table at `docs/briefs/bridge-retirement-audit-sourcespan-family.md` updated to mark **rows #2 + #6 only** retired with this PR's # citation (rows #1, #3-5, #7-19 remain under their owners; umbrella row advances to `Retired` only when ALL production sites are retired across owner-scoped PRs). -4. `dag.rs::bridge_source_span_file_participation_retired` ratchet test passes (authored by Verification per the **Cross-Mgr prerequisite** gate above; confirmed-present at HEAD before this PR merges). +4. **No umbrella-ratchet pre-merge gate** (per Cross-Mgr coordination section): the umbrella `bridge_source_span_file_participation_retired` ratchet predicate cannot flip green on this slice alone — production sites in `lens_apply.rs` / `lower.rs` / `emit.rs` remain post-this-PR. Worker does NOT wait for Verification ratchet authoring. Acceptance for this slice is the audit-packet receipt update in #3 above; Verification's ledger-zero audit progress field updates **post-merge**. 5. Bootstrap regen: `cargo test -p v3-compiler bootstrap_regen_fresh -- --ignored` clean (path-string deletion must not perturb regen byte-snapshot). 6. Full suite: `cargo test --workspace --exclude v2-compiler-tests` green; `cargo clippy --all-targets -- -D warnings` clean. @@ -67,7 +67,7 @@ Authority constants: `BOOL_TYPES_FILE` (`dsl/std/types.dag`), `PIPELINE_AUTHORIT ## Cross-Mgr handoff - **PB Mgr**: audit row #6's sibling (`bridge_include_str_side_channels_retired` for `pipeline_authority.rs` compile-body drift) is PB-owned; this Substrate slice does NOT touch the include_str path, only the diagnostic-span path. No cross-PR coordination needed unless audit row interpretation drifts at execution time. -- **Verification Mgr**: ratchet authoring + ledger-zero audit advancement. +- **Verification Mgr**: post-merge ledger-zero audit progress update (per `r3-v-bridge-retirement-ledger-zero-audit.md`); no same-slice ratchet authoring required for this slice. ## Worker disposition From 5b3a9f8405e95960b9f4198b1dc943910f82bb2c Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 01:47:35 -0400 Subject: [PATCH 07/27] =?UTF-8?q?WIP:=20R3=20Substrate=20Mgr=20=E2=80=94?= =?UTF-8?q?=20lane=20through=20R3=20close?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- ...strate-s5-coproduct-projection-carrier-worker.md | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md b/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md index eed5d47105e..264c0d059d9 100644 --- a/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md +++ b/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md @@ -25,13 +25,18 @@ type CoproductProjection { `WireTagValue` MUST be a typed leaf (sum type or named record), **not** `String`. If Anthropic + REST both serialize as string at the wire boundary, encode the typed-on-our-side / serialized-at-emit pattern: `WireTagValue` stays typed in substrate; serialization adapter handles `String <-> WireTagValue` at the wire boundary. -### Substrate observations the worker must surface (do not silently work around) +### Substrate observations — Director pre-ratified dispositions (gunbc#828 #issuecomment-4394416049) -1. **`DeclarationRef = String` alias at `dsl/std/serialization.dag:16`** — Director's ratification framing emphasizes "typed key, not string identity (avoids audit row #14 collision)". The current `DeclarationRef` IS a String alias. If `CoproductProjection.declaration: DeclarationRef` is to be a real typed key, either (a) `DeclarationRef` itself must promote to a structural typed shape (e.g., `(module: ModuleId, name: DeclarationName)` record) — substantial substrate change, surface as scope question; OR (b) accept the alias as a soft-typed nominal handle for this carrier slice and note the future-promotion debt. **STOP-and-PING the Mgr** before proceeding; don't choose silently. +These were flagged as STOP-and-PING in canvas; Director pre-ratified the dispositions so worker can proceed without re-pinging unless evidence forces escalation. -2. **`FieldRef` does not exist at HEAD** as a standalone type (only `InputFieldRef` mentioned in `services.dag:34`). The brief asks for a typed `FieldRef` carrier. Either reuse `InputFieldRef` if its semantics generalize, or introduce `FieldRef` alongside `CoproductProjection`. Choose pragmatically; don't introduce a parallel-authority second `FieldRef`. +1. **`DeclarationRef = String` alias at `dsl/std/serialization.dag:16`** — **Disposition: (b) accept alias for this slice + debt note.** Promoting `DeclarationRef` to structural typed shape mid-slice is cascade scope creep per `feedback_construction_over_ratchets`. Document the soft-typed nominal handle in `CoproductProjection` carrier comments; add a debt-paydown row pointing at future structural promotion of `DeclarationRef`. **Re-escalate to Mgr only if** worker surfaces evidence the alias actively breaks something same-slice (e.g., Anthropic #1702 wiring triggers a string-identity bridge per `feedback_opaque_strings_attract_heuristics`). -3. **`InternallyTaggedObject.tag_field: String`** at `dsl/std/serialization.dag:49` already uses a String tag-field. The new typed `FieldRef` shape will create a typed/string asymmetry between the two carriers. Either (a) `CoproductProjection.wire_tag_field` is `FieldRef` and the asymmetry is documented as tracked debt (eventually `InternallyTaggedObject` migrates), or (b) accept `String` for `wire_tag_field` to match. Director's binding constraint #2 is explicit: typed leaf `WireTagValue`; the `wire_tag_field` field shape is less hard-binding. Recommend (a) — typed introduction here, debt note for `InternallyTaggedObject` migration. +2. **`FieldRef` does not exist at HEAD; only `InputFieldRef` at `services.dag:34`** — **Disposition: grep-decide between two structural patterns.** Worker greps `services.dag` + adjacent surface for `InputFieldRef` consumers BEFORE deciding (per `feedback_emitter_workaround_is_gap_symptom` + `feedback_audit_adjacent_authority_first`): + - If `InputFieldRef` carries input-specific structural context → introduce `FieldRef` as the general carrier; treat `InputFieldRef` as specialization (compose, not parallel-author). + - If `InputFieldRef` is just narrowly-named for an input use-case → rename to `FieldRef` (per `feedback_naming_is_aliasing` — rename is structural-cheap). + - **Do NOT** manufacture a parallel-authority second `FieldRef`. + +3. **`InternallyTaggedObject.tag_field: String` asymmetry at `dsl/std/serialization.dag:49`** — **Disposition: typed introduction here + debt note for future migration.** Per `feedback_parallel_representation_debt`, the typed/string asymmetry is recorded as known shape mismatch with named dissolution (eventual `InternallyTaggedObject.tag_field: FieldRef` migration). Do NOT fix in same slice unless evidence shows the asymmetry actively blocks a downstream consumer. ## Acceptance gates (same-slice, all must pass) From 2900228b381a531afaa5d6a0e3ee67dd5dda8efe Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 05:47:48 +0000 Subject: [PATCH 08/27] =?UTF-8?q?docs(briefs):=20S5=20brief=20=E2=80=94=20?= =?UTF-8?q?absorb=20Director=20pre-ratifications=20for=203=20STOP-and-PING?= =?UTF-8?q?=20items?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049: 1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break) 2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename 3. tag_field String asymmetry: typed introduction + debt note for migration Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria section narrowed accordingly. Co-Authored-By: Claude Opus 4.7 (1M context) --- .../r3-substrate-s5-coproduct-projection-carrier-worker.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md b/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md index 264c0d059d9..aaa3d188087 100644 --- a/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md +++ b/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md @@ -50,8 +50,8 @@ These were flagged as STOP-and-PING in canvas; Director pre-ratified the disposi ## STOP / PING criteria - **STOP** before proceeding if: - - `DeclarationRef` typed-promotion question (substrate observation #1) cannot be answered locally — surface to Mgr (warm-wolf-698 / inbox #2068). - - `FieldRef` introduction cascades into emit/typecheck surfaces beyond `coproduct_projection.dag` and the chosen consumer paydown — surface scope-creep. + - Substrate observation #1 (`DeclarationRef` alias): evidence emerges mid-slice that the alias actively breaks something (e.g., string-identity bridge on Anthropic #1702 wire) — re-escalate; default disposition (b) otherwise applies without re-ping. + - Substrate observation #2 (`FieldRef` introduction): cascades into emit/typecheck surfaces beyond `coproduct_projection.dag` + the chosen consumer paydown — surface scope-creep. - At carrier-shape implementation time, `WireTagValue` typed-leaf shape forces a String<->typed adapter that has nontrivial bootstrap-regen impact — surface. - **PING** PB Mgr (#2074 / `warm-dove-618`) at carrier-landing time per Director's cross-Mgr coordination note: PB owns `T-LensProducer-Retirement` which may consume similar projection shapes. They may have downstream needs constraining the carrier. **This is a heads-up, not a same-slice blocker** — PB's input refines future iterations. From 0e8724bccbdb656c637cbdd6ea46b47c3e75ef46 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 05:56:33 +0000 Subject: [PATCH 09/27] =?UTF-8?q?docs(r3):=20Q-Reification=20Gate=20A=20re?= =?UTF-8?q?ceipt=20=E2=80=94=20Option=20A=20(Dag-as-carrier)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge at PR #2096 (commit fec869202): src/v3/std/substrate.dag::Dag IS the reflected program; no new substrate carrier required. ReflectedProgram rejected. Gate A patches: 1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096 merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition). 2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3 producer dependency. Replaces ReflectedProgram with consumer-wiring nuance: lens fold consumes Dag via .dag body authority through Evaluator. 3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred work is consumer-wiring, NOT a separate carrier. 4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag reframe. Receipt of pass-by-construction: this PR adds NO new .dag declaration to src/v3/std/. The ratification is structurally a non-addition (Option A correctness proof per same-slice dissolution discipline). Co-Authored-By: Claude Opus 4.7 (1M context) --- .../r3-pr-e6-g1a-option3-static-lens-worker.md | 12 +++++++++--- ...r3-pr-e8-w1-producer-contract-test-plan-worker.md | 6 ++++-- docs/briefs/r3-v-pattern-a-tc1-v1-worker.md | 6 +++--- docs/r3-program-plan.md | 1 + 4 files changed, 17 insertions(+), 8 deletions(-) diff --git a/docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md b/docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md index e1b011f1213..b045265b467 100644 --- a/docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md +++ b/docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md @@ -13,7 +13,10 @@ whose non-function fields are projected through the evaluator, and whose carrier. This is not a reflected-program fold. Lens-over-`Dag` folding is deferred to -Q-Reification / `ReflectedProgram` typed declaration-reference carrier work. +follow-on consumer-wiring work (`Dag` IS the reflected program per Q-Reification +Option A ratified 2026-05-07 [#2096](https://github.com/gunb-ai/gunbc/pull/2096); +the deferred work is **wiring lens-fold consumers through `.dag` body authority +via the Evaluator**, NOT a separate `ReflectedProgram` carrier). ## Context @@ -143,8 +146,11 @@ The implementation PR must demonstrate: 7. The test proves no `lens_apply`, `eval_substrate_reify`, or reflection helper is imported or called. 8. PR body explicitly says: this is a lens consumer-wiring mechanism - demonstration; lens-over-`Dag` folding is deferred to - `ReflectedProgram` / typed declaration-reference carrier work. + demonstration; lens-over-`Dag` folding is deferred to follow-on + consumer-wiring (`Dag` IS the reflected program per Q-Reification Option A + ratified 2026-05-07 [#2096](https://github.com/gunb-ai/gunbc/pull/2096); the + deferred work is wiring fold consumers through `.dag` body authority via the + Evaluator, NOT a separate `ReflectedProgram` carrier). Validation should be the narrowest relevant test target plus any repository format/check command normally required for touched files. diff --git a/docs/briefs/r3-pr-e8-w1-producer-contract-test-plan-worker.md b/docs/briefs/r3-pr-e8-w1-producer-contract-test-plan-worker.md index 6543123796d..b191760dde0 100644 --- a/docs/briefs/r3-pr-e8-w1-producer-contract-test-plan-worker.md +++ b/docs/briefs/r3-pr-e8-w1-producer-contract-test-plan-worker.md @@ -181,8 +181,10 @@ slice requires any of these: - broadening W1 beyond Rust / Int / one named output bind before typed observation authority lands; - treating #1857 as runner, E8, Q-Reification, or lens-over-`Dag` authority; -- using `lens_apply.rs`, reflected-program folding, or `ReflectedProgram` to - justify W1; +- using `lens_apply.rs`, reflected-program folding, or fold-over-`Dag` (per + Q-Reification Option A ratified 2026-05-07 [#2096](https://github.com/gunb-ai/gunbc/pull/2096), + `Dag` IS the reflected program; no separate `ReflectedProgram` carrier exists) + to justify W1; - executing fixture `rust_emit_output` / `dag_eval_output` stub bodies as producer semantics; - comparing emitted source, raw stdout bytes, diagnostics, or exit code as diff --git a/docs/briefs/r3-v-pattern-a-tc1-v1-worker.md b/docs/briefs/r3-v-pattern-a-tc1-v1-worker.md index 311f18705b8..5fd6e7144c0 100644 --- a/docs/briefs/r3-v-pattern-a-tc1-v1-worker.md +++ b/docs/briefs/r3-v-pattern-a-tc1-v1-worker.md @@ -1,6 +1,6 @@ # R3 Pattern-A — TC1 first executable slice (V1) Worker Brief -**Status:** **HELD** — **Q-Reification** STOP + **Director η non-vacuity (Branch B)** 2026-05-06 ([gunbc#828](https://github.com/gunb-ai/gunbc/issues/828)). **Q-PAFS Path A** remains **ACCEPTED** (PR [#1824](https://github.com/gunb-ai/gunbc/pull/1824) merge record on `main`). **V1 (`tc1_eta_equivalence_executable`) unpairs** from Evaluator **E3 Option 3** narrow **argument-opaque** representative slice for **TC1 acceptance** — that shape yields **vacuous** `BinaryDimensionReportEquals` (constant `DimensionReport`); it cannot honestly close the gate against [`r3-v-tc1-eta-equivalence-deeper-analysis.md`](r3-v-tc1-eta-equivalence-deeper-analysis.md) §What TC1 Asserts + §Strict-Fire Extension Surface. **Resume dispatch** only after **Q-Reification + ReflectedProgram\** (real lens-over-Dag fold, non-vacuous η obligation) **or** Director-visible §1.8 / program-plan semantics revision (explicit “plumbing-only” TC1 milestone — **not** ratified 2026-05-06). **Pre-auth queue:** patch this brief when Q-Reification / carrier land — do **not** replace wholesale. +**Status:** **HELD** — **Director η non-vacuity (Branch B)** 2026-05-06 ([gunbc#828](https://github.com/gunb-ai/gunbc/issues/828)). **Q-Reification CLEARED 2026-05-07** ([Option A ratified](https://github.com/gunb-ai/gunbc/pull/2096), `Dag` IS the reflected program; no separate carrier). **Q-PAFS Path A** remains **ACCEPTED** (PR [#1824](https://github.com/gunb-ai/gunbc/pull/1824) merge record on `main`). **V1 (`tc1_eta_equivalence_executable`) unpairs** from Evaluator **E3 Option 3** narrow **argument-opaque** representative slice for **TC1 acceptance** — that shape yields **vacuous** `BinaryDimensionReportEquals` (constant `DimensionReport`); it cannot honestly close the gate against [`r3-v-tc1-eta-equivalence-deeper-analysis.md`](r3-v-tc1-eta-equivalence-deeper-analysis.md) §What TC1 Asserts + §Strict-Fire Extension Surface. **Resume dispatch** only after lens fold consumes `Dag` via `.dag` body authority through Evaluator (real lens-over-Dag fold, non-vacuous η obligation) **or** Director-visible §1.8 / program-plan semantics revision (explicit "plumbing-only" TC1 milestone — **not** ratified 2026-05-06). **Q-Reification gate is cleared**; remaining hold is Branch B η non-vacuity only. **Parent:** [`docs/briefs/r3-verification-manager.md`](r3-verification-manager.md) — absorbed formal-grounding / Pattern-A cluster (not a fourth lane; see [`docs/r3-structure.md`](../r3-structure.md) §"Manager structure"). @@ -26,7 +26,7 @@ Gates **#12–#14** (TC2 / TC3 / RustDagIsomorphism executables) stay **DECLARED | --- | --- | --- | | **Primary** | **bold-crane-790** ([gunbc#1748](https://github.com/gunb-ai/gunbc/issues/1748)) | **Track A** ( **V6** ledger audit, TC2/TC3/RustDagIso, partner-scope PRs per schedule): when session active **and** **V6** reaches a **clean checkpoint** acceptable to Verification Mgr — route **those** PRs through bold-crane. **`tc1_eta_equivalence_executable` / TC1 V1 slice excluded** until Branch B hold clears (above). | | **Alternate** | **New worker** (spawn per `feedback_idle_workers_dispatchable_directly`) | If bold-crane saturated on **V6** or archived — substitute for **non-TC1-V1** Track A work; do **not** interpret as TC1 dispatch unblock. | -| **TC1 V1** | bold-crane (when **unheld**) | Same primary pin resumes **only** when **Q-Reification + ReflectedProgram\** (or revised §1.8 TC1 semantics) satisfies non-vacuous η per Director ratification. | +| **TC1 V1** | bold-crane (when **unheld**) | Same primary pin resumes **only** when lens fold over `Dag` (per Q-Reification Option A; `Dag` IS the reflected program) consumes `.dag` body authority through Evaluator with non-vacuous η obligation, **or** revised §1.8 TC1 semantics satisfies non-vacuous η per Director ratification. | **cool-heron-521** remains on **V2 / V4 / V5** prep per partition; **not** the default home for V1 unless explicitly redirected. @@ -51,7 +51,7 @@ Hold **without** widening by inertia: | Dependency | Owner | Why | | --- | --- | --- | -| **E6-G1.a / E3 producer** | Evaluator Mgr | Fold must yield reports that **depend on reflected program shape** enough for **non-vacuous η-invariance** — **not** satisfied by **argument-opaque** `read`/`validate` (PR #1844 strict shape). **Blocked** until **Q-Reification** + **ReflectedProgram\** (or equivalent) lands **and** STOP clears; then TC1 V1 may re-pair on **ratified** producer contract. | +| **E6-G1.a / E3 producer** | Evaluator Mgr | Fold must yield reports that **depend on reflected program shape** enough for **non-vacuous η-invariance** — **not** satisfied by **argument-opaque** `read`/`validate` (PR #1844 strict shape). **Q-Reification cleared 2026-05-07 (Option A: `Dag` IS the reflected program)**; remaining block is non-vacuous η obligation via lens fold consuming `Dag` body authority through Evaluator. TC1 V1 re-pairs on ratified producer contract once that fold lands. | | **T-Substrate-Lens-Primitive + lens producer retirement progress** | Substrate / PB lanes | Path A assumes existing fold machinery; no parallel `lens_apply` interpretation for the fold receipts. | | **Representative lens set + eta pair declaration refs** | Substrate (facts) + Verification (fixture refs) | Finite, Director-visible set enumerated in `.dag` / declarations — not “all `Lens`” in V1. | diff --git a/docs/r3-program-plan.md b/docs/r3-program-plan.md index f01e869be9e..ceef9abb875 100644 --- a/docs/r3-program-plan.md +++ b/docs/r3-program-plan.md @@ -993,6 +993,7 @@ Substrate canvas + plan-poke-hole both folded in. Key absorptions: | Q-Slice-C-Retirement-Receipt | Slice C → :425 retirement receipt: Mgr-tier vs worker authoring; single combined vs per-slice | Mgr-tier authoring; single combined receipt covering Slice A+B+C (Brian-style condensation per `feedback_brief_pr_cadence`). | RATIFIED-by-default (Substrate Mgr C3) | | Q-Substrate-Grounding-DAG-Routing | Slice C residual `.dag` files overlap Grounding scope (`docs/parallelism-design.md` etc.) — routing | Substrate Mgr owns Slice C residual entirely; cross-Mgr coord with bold-ferret-748 for Grounding-impacting `.dag` content via comment-thread review (no separate Grounding dispatch). | RATIFIED-by-default (Substrate Mgr C4) | | Q-Substrate-Cadence-Throughput | 10 wait-window briefs in PR #1782 + 6+ substrate carrier dispatches form serialized queue; rate-limits R3 close | Authorize parallel-dispatch where lanes have no shared prerequisite (T-E-P + L6 + Numeric-Construction parallel; X1.b sequenced post-E6-G0c; coproduct paydowns sequenced post-variant-aware carrier). PM tracks cadence in §9 weekly cadence; lane-owning Mgr packages PR-sized specs. | RATIFIED-by-default (Substrate Mgr E1+E2) | +| Q-Reification | Substrate-fact-introduction (P1 procedure) for compiled-Dag → evaluator-Value reification — does R3 require a new `ReflectedProgram` carrier, or is `src/v3/std/substrate.dag::Dag` already the reflected program? | **Option A (Dag-as-carrier) ratified** — `Dag` IS the reflected program; no new substrate carrier required. `ReflectedProgram` rejected (4-fail per `feedback_no_metadata_markers` + `feedback_parallel_representation_debt` + `feedback_dissolve_bridges` + `INVARIANTS.md` C-1). Proposal landed at [PR #2096](https://github.com/gunb-ai/gunbc/pull/2096) (merge commit `fec869202`, 2026-05-07); receipt = pass-by-construction (no new `.dag` declaration added to `src/v3/std/`). | **RATIFIED 2026-05-07 (Option A)** — Gate A receipt PR (Substrate Mgr): brief patches `ReflectedProgram` → `Dag` across `r3-v-pattern-a-tc1-v1-worker.md` + `r3-pr-e6-g1a-option3-static-lens-worker.md` + `r3-pr-e8-w1-producer-contract-test-plan-worker.md`; #1960 closed-as-non-addition. Gate B (Verification TC1 V1 lens body in `.dag` + Evaluator E3.c representative consumes `Dag`) coordinates separately. | | Q-Lens-Behavioral-Parity-R3-Closeability | **WAS RED** (T-Lens-Behavioral-Parity 4-lens scope L-XL + 4 sub-slices per lens + T-E-P-Producer-Broadening foundational dep; Substrate Mgr honest assessment: may not close cleanly in R3 timeline). **Substrate Mgr S2 canvas authored 2026-05-06** (`docs/briefs/r3-substrate-s2-t-lbp-scope-calibration-canvas.md`): per-lens × per-sub-slice blocker matrix (16 cells); option (a) full T-LBP / option (b) narrow to complexity+cost / option (c) substrate-gap subdivision feasibility analysis. | **Director ratified option (b) 2026-05-06** at [gunbc#828 #issuecomment-4385329180](https://github.com/gunb-ai/gunbc/issues/828#issuecomment-4385329180) (zesty-bear-812 Director session; cross-relayed via deep-wolf-155 propagation PR). **Q1 (option a) REJECTED**: requires landing 4c (caller-side effect-set pinning carrier) inside R3 — substrate-fact-introduction-without-confirmed-bridge-consumer; circular against R3 close per `INVARIANTS.md` P1. **Q2 (option b) RATIFIED**: T-LBP narrows to **complexity + cost lenses only** in R3 (both share T-E-P producer dependency; closing simultaneously is critical-path fastest). **Carved to R4** per `docs/r4-carve-out-routing.md` (commit `811de219f`): C1 parallelism lens (Stage 2e walker port substrate exists; port + rewire), C2 effect_enumeration lens (4c carrier P1 substrate-fact-introduction required), C3 #83 register zero-proxy/zero-stub narrowed to in-R3 lenses (complexity + cost) with parallelism + effect_enum entries documented as R4-carved. Q3 N/A. | **RATIFIED 2026-05-06 (option b)** — T-LBP R3 scope = complexity + cost lenses only; parallelism + effect_enum + register-narrow carved to R4 per canonical routing ledger. | --- From 2601d7d263449cb81bb66004a1492b2589afe366 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 06:03:32 +0000 Subject: [PATCH 10/27] =?UTF-8?q?docs(briefs):=20S5=20=E2=80=94=20delete?= =?UTF-8?q?=20superseded=20canvas=20+=20name=20dissolution=20trigger=20for?= =?UTF-8?q?=20tag=5Ffield=20asymmetry?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority + P5 dissolution trigger). Fixes: 1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md (superseded by the γ-ratified worker brief in same PR; would otherwise leave two current-looking S5 status authorities post-merge — one saying ratification pending, one saying γ ratified). 2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a binding named dissolution trigger: when FieldRef exists as top-level carrier AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative debt ledger before merging carrier-introduction PR. Co-Authored-By: Claude Opus 4.7 (1M context) --- ...-s5-coproduct-projection-carrier-worker.md | 2 +- ...variant-aware-projection-carrier-canvas.md | 79 ------------------- 2 files changed, 1 insertion(+), 80 deletions(-) delete mode 100644 docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md diff --git a/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md b/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md index aaa3d188087..06bdd6a0c58 100644 --- a/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md +++ b/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md @@ -36,7 +36,7 @@ These were flagged as STOP-and-PING in canvas; Director pre-ratified the disposi - If `InputFieldRef` is just narrowly-named for an input use-case → rename to `FieldRef` (per `feedback_naming_is_aliasing` — rename is structural-cheap). - **Do NOT** manufacture a parallel-authority second `FieldRef`. -3. **`InternallyTaggedObject.tag_field: String` asymmetry at `dsl/std/serialization.dag:49`** — **Disposition: typed introduction here + debt note for future migration.** Per `feedback_parallel_representation_debt`, the typed/string asymmetry is recorded as known shape mismatch with named dissolution (eventual `InternallyTaggedObject.tag_field: FieldRef` migration). Do NOT fix in same slice unless evidence shows the asymmetry actively blocks a downstream consumer. +3. **`InternallyTaggedObject.tag_field: String` asymmetry at `dsl/std/serialization.dag:49`** — **Disposition: typed introduction here + debt note for future migration with named dissolution trigger.** Per `feedback_parallel_representation_debt`, the typed/string asymmetry is recorded as known shape mismatch. **Dissolution trigger** (binding per P5 scaffold/debt discipline): when **(a)** `FieldRef` exists as a typed top-level carrier in the substrate AND **(b)** `InputFieldRef` (currently at `services.dag:34`) has been classified — either retained as input-scoped specialization or renamed to general `FieldRef` per substrate observation #2 above — THEN migrate `InternallyTaggedObject.tag_field: String` → `InternallyTaggedObject.tag_field: FieldRef` in a follow-on Substrate hygiene PR (analogous to Q2 `result_port` canonical rename per Substrate Mgr standing dispatch authority). Worker MUST add a debt-paydown row to `docs/debt/r3-debt-paydown-ledger-2026-05-02.md` (or current authoritative debt ledger at HEAD) naming this carrier + dissolution trigger before merging the carrier-introduction PR. Do NOT fix in same slice unless evidence shows the asymmetry actively blocks a downstream consumer. ## Acceptance gates (same-slice, all must pass) diff --git a/docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md b/docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md deleted file mode 100644 index 3cf0e4bc62e..00000000000 --- a/docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md +++ /dev/null @@ -1,79 +0,0 @@ -# Canvas — Substrate S5 Variant-aware projection metadata carrier - -**Sub-issue**: gunbc#1947 (parented under #1939 Substrate Mgr lane). -**Authority**: `docs/r3-design-schedule-2026-05-06.md` §S5 (lines 101-106); `docs/r3-program-plan.md:979` Q-Anthropic-Variant-Aware (RATIFIED-by-default — all 3 paydowns); Substrate canvas C1. -**Status**: **canvas — Director-tier ratification needed on carrier shape before worker brief authoring**. - -## Scope - -Typed REST response projection carrier for **coproduct response bodies** — the substrate fact that lets a typed REST response `from`-path resolver dispatch on a sum-type response variant rather than collapsing into untyped JSON. - -Closure: §1.8 gates #29-#30 (T-Anthropic-Wire 2 gates); unblocks #1702 Anthropic re-dispatch + 3 follow-up paydown PRs (Anthropic Messages 200 residual + 2 sibling coproduct slices already-briefed at `r3-coproduct-{2,3}-*.md`). - -## Why a canvas not a worker brief - -Carrier shape is a **substrate-fact-introduction (P1 procedure)** with non-trivial design space. Authoring a worker brief without Director ratification of shape risks rework. Surfacing 3 carrier-shape options for ratification. - -## Carrier-shape options - -### Option α — Variant-tag projection on `RestResponseProjection` - -Extend the existing `RestResponseProjection` carrier (if extant; else introduce alongside `CoproductWireContract` at `dsl/extdeps/llm/anthropic.dag:20-30` precedent) with a per-variant projection field: - -```dag -type RestResponseProjection - = { request_path: String - , response_variant_tag: String - , response_body_field: List - } -``` - -Indexed by `(method, response_variant_tag)`. Resolver picks the matching projection by parsing the response wire-tag (e.g., `type` discriminator in Anthropic's content-block coproducts) and dispatching to the variant's projection. - -**Pro**: minimal new substrate; reuses `FieldProjection` shape; aligns with `CoproductWireContract::InternallyTaggedObject` (which Anthropic uses already at `:20-30`). -**Con**: tag-string IS a bridge — the rank-table risk of audit-row #14 family. Acceptable because tag strings are wire-protocol identity (not internal compiler identity), but worth flagging. - -### Option β — Sum-type metadata on `Declaration` - -Generalize: every coproduct `Declaration` carries optional `variant_projection_metadata: Option>`. The resolver finds the declaration via existing identity surface (declaration_by_name or DeclarationRef) and picks variant by structural variant-id, not wire string. - -**Pro**: structural — no string bridge. Reuses sum-type variant identity already in `Declaration` (TypeBody::Sum variant constructors per VariantConstruct lowerer at memory/MEMORY.md:201). -**Con**: heavier substrate change; couples REST-response-specific concern to general `Declaration`. May leak to other coproduct uses without need. - -### Option γ — Free-standing `CoproductProjection` carrier - -New top-level carrier in `dsl/extdeps/llm/wire_contracts.dag` (or similar): - -```dag -type CoproductProjection - = { coproduct_decl: DeclarationRef - , wire_tag_field: String // e.g., "type" - , variant_projections: Map - } -``` - -Lookup: `coproduct_projection_for(decl: DeclarationRef) -> CoproductProjection`. Wire-tag string lives in projection data, not in identity dispatch. - -**Pro**: localizes the wire-coproduct-dispatch concern to one named carrier; avoids polluting `Declaration`. DeclarationRef-keyed (not span.file-keyed) — clean of audit-row-#14 concerns. -**Con**: new carrier type; some duplication if `RestResponseProjection` already carries a similar shape. - -## Director ratification ask - -1. **Pick α / β / γ** (or surface a fourth option). Provisional Mgr-tier recommendation: **γ** — DeclarationRef-keyed, localized to wire-protocol concern, doesn't leak into `Declaration` general surface, avoids the tag-string-as-identity concern of α. -2. Confirm scope: carrier-only at S5, or carrier + 1 of 3 paydowns bundled? Current default per Q-Anthropic-Variant-Aware = carrier + ALL 3 paydowns separately (already briefed). Confirm S5 dispatch is **carrier-only**; the 3 paydowns dispatch in their own briefs. - -## On ratification — worker brief scope - -Will author execution brief covering: -- New carrier definition in chosen location (`dsl/extdeps/llm/wire_contracts.dag` per γ, or alternate per ratification) -- Indexing API (`coproduct_projection_for(decl) -> CoproductProjection` or analog) -- Resolver wiring point in `from`-path resolution (typed REST response projection consumer) -- Acceptance: §1.8 gates #29-#30 advance from declared → carrier-landed; #1702 branch unparks -- Bootstrap regen + clippy + workspace tests green -- Cross-Mgr handoff: 3 coproduct paydown briefs already authored (`r3-coproduct-{1,2,3}-*-worker.md`) ready to dispatch in their own PRs post-S5 land - -## Worker pin candidates (post-ratification) - -valiant-ibex-312 (recently freed post-#1933 IntPlatform/UIntPlatform land — substrate-fact-introduction precedent owner) OR smart-ram-167. Final pin at dispatch. - -— Authored by warm-wolf-698 (Substrate Mgr) 2026-05-07 per Director endorsement at gunbc#828 #issuecomment-4394293399 of authoring next 2-3 unbriefed items. From 1b9f743ed1ec67d615e61f5d75a4efecb7032a6d Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 06:07:52 +0000 Subject: [PATCH 11/27] =?UTF-8?q?docs(r3):=20Q-Reification=20row=20?= =?UTF-8?q?=E2=80=94=20fix=20invariant=20cite=20(C-1=20=E2=86=92=20P2)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed: INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3 fail-closed family), not parallel-representation/duplicate-authority. The correct cite for rejecting a parallel ReflectedProgram alongside Dag is P2 single authority (INVARIANTS.md line 148: cost of change is proportional to how many files encode the same fact). Cite updated to "INVARIANTS.md P2 single authority" with inline gloss. Co-Authored-By: Claude Opus 4.7 (1M context) --- docs/r3-program-plan.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/r3-program-plan.md b/docs/r3-program-plan.md index ceef9abb875..06dfef50c14 100644 --- a/docs/r3-program-plan.md +++ b/docs/r3-program-plan.md @@ -993,7 +993,7 @@ Substrate canvas + plan-poke-hole both folded in. Key absorptions: | Q-Slice-C-Retirement-Receipt | Slice C → :425 retirement receipt: Mgr-tier vs worker authoring; single combined vs per-slice | Mgr-tier authoring; single combined receipt covering Slice A+B+C (Brian-style condensation per `feedback_brief_pr_cadence`). | RATIFIED-by-default (Substrate Mgr C3) | | Q-Substrate-Grounding-DAG-Routing | Slice C residual `.dag` files overlap Grounding scope (`docs/parallelism-design.md` etc.) — routing | Substrate Mgr owns Slice C residual entirely; cross-Mgr coord with bold-ferret-748 for Grounding-impacting `.dag` content via comment-thread review (no separate Grounding dispatch). | RATIFIED-by-default (Substrate Mgr C4) | | Q-Substrate-Cadence-Throughput | 10 wait-window briefs in PR #1782 + 6+ substrate carrier dispatches form serialized queue; rate-limits R3 close | Authorize parallel-dispatch where lanes have no shared prerequisite (T-E-P + L6 + Numeric-Construction parallel; X1.b sequenced post-E6-G0c; coproduct paydowns sequenced post-variant-aware carrier). PM tracks cadence in §9 weekly cadence; lane-owning Mgr packages PR-sized specs. | RATIFIED-by-default (Substrate Mgr E1+E2) | -| Q-Reification | Substrate-fact-introduction (P1 procedure) for compiled-Dag → evaluator-Value reification — does R3 require a new `ReflectedProgram` carrier, or is `src/v3/std/substrate.dag::Dag` already the reflected program? | **Option A (Dag-as-carrier) ratified** — `Dag` IS the reflected program; no new substrate carrier required. `ReflectedProgram` rejected (4-fail per `feedback_no_metadata_markers` + `feedback_parallel_representation_debt` + `feedback_dissolve_bridges` + `INVARIANTS.md` C-1). Proposal landed at [PR #2096](https://github.com/gunb-ai/gunbc/pull/2096) (merge commit `fec869202`, 2026-05-07); receipt = pass-by-construction (no new `.dag` declaration added to `src/v3/std/`). | **RATIFIED 2026-05-07 (Option A)** — Gate A receipt PR (Substrate Mgr): brief patches `ReflectedProgram` → `Dag` across `r3-v-pattern-a-tc1-v1-worker.md` + `r3-pr-e6-g1a-option3-static-lens-worker.md` + `r3-pr-e8-w1-producer-contract-test-plan-worker.md`; #1960 closed-as-non-addition. Gate B (Verification TC1 V1 lens body in `.dag` + Evaluator E3.c representative consumes `Dag`) coordinates separately. | +| Q-Reification | Substrate-fact-introduction (P1 procedure) for compiled-Dag → evaluator-Value reification — does R3 require a new `ReflectedProgram` carrier, or is `src/v3/std/substrate.dag::Dag` already the reflected program? | **Option A (Dag-as-carrier) ratified** — `Dag` IS the reflected program; no new substrate carrier required. `ReflectedProgram` rejected (4-fail per `feedback_no_metadata_markers` + `feedback_parallel_representation_debt` + `feedback_dissolve_bridges` + `INVARIANTS.md` **P2 single authority** — adding a parallel `ReflectedProgram` carrier alongside `Dag` would introduce duplicate authority for the same structural fact). Proposal landed at [PR #2096](https://github.com/gunb-ai/gunbc/pull/2096) (merge commit `fec869202`, 2026-05-07); receipt = pass-by-construction (no new `.dag` declaration added to `src/v3/std/`). | **RATIFIED 2026-05-07 (Option A)** — Gate A receipt PR (Substrate Mgr): brief patches `ReflectedProgram` → `Dag` across `r3-v-pattern-a-tc1-v1-worker.md` + `r3-pr-e6-g1a-option3-static-lens-worker.md` + `r3-pr-e8-w1-producer-contract-test-plan-worker.md`; #1960 closed-as-non-addition. Gate B (Verification TC1 V1 lens body in `.dag` + Evaluator E3.c representative consumes `Dag`) coordinates separately. | | Q-Lens-Behavioral-Parity-R3-Closeability | **WAS RED** (T-Lens-Behavioral-Parity 4-lens scope L-XL + 4 sub-slices per lens + T-E-P-Producer-Broadening foundational dep; Substrate Mgr honest assessment: may not close cleanly in R3 timeline). **Substrate Mgr S2 canvas authored 2026-05-06** (`docs/briefs/r3-substrate-s2-t-lbp-scope-calibration-canvas.md`): per-lens × per-sub-slice blocker matrix (16 cells); option (a) full T-LBP / option (b) narrow to complexity+cost / option (c) substrate-gap subdivision feasibility analysis. | **Director ratified option (b) 2026-05-06** at [gunbc#828 #issuecomment-4385329180](https://github.com/gunb-ai/gunbc/issues/828#issuecomment-4385329180) (zesty-bear-812 Director session; cross-relayed via deep-wolf-155 propagation PR). **Q1 (option a) REJECTED**: requires landing 4c (caller-side effect-set pinning carrier) inside R3 — substrate-fact-introduction-without-confirmed-bridge-consumer; circular against R3 close per `INVARIANTS.md` P1. **Q2 (option b) RATIFIED**: T-LBP narrows to **complexity + cost lenses only** in R3 (both share T-E-P producer dependency; closing simultaneously is critical-path fastest). **Carved to R4** per `docs/r4-carve-out-routing.md` (commit `811de219f`): C1 parallelism lens (Stage 2e walker port substrate exists; port + rewire), C2 effect_enumeration lens (4c carrier P1 substrate-fact-introduction required), C3 #83 register zero-proxy/zero-stub narrowed to in-R3 lenses (complexity + cost) with parallelism + effect_enum entries documented as R4-carved. Q3 N/A. | **RATIFIED 2026-05-06 (option b)** — T-LBP R3 scope = complexity + cost lenses only; parallelism + effect_enum + register-narrow carved to R4 per canonical routing ledger. | --- From 55470a1a1a7d8d316d531adc58b9063e61860d71 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 06:17:52 +0000 Subject: [PATCH 12/27] =?UTF-8?q?docs(briefs):=20S5=20=E2=80=94=20name=20d?= =?UTF-8?q?issolution=20trigger=20for=20DeclarationRef=20alias=20debt?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired endpoint ("future structural promotion of DeclarationRef") but no checkable dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed for in commit 2601d7d26. Trigger now binding: promote DeclarationRef when EITHER (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name rank-table) closes — dsl/std ↔ src/v3/std module convergence makes name-keyed identity unambiguous and structural module identity available, OR (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per feedback_opaque_strings_attract_heuristics (heuristic patching, naming- convention dispatch, suffix/prefix matching). Worker MUST add debt-paydown row before merging carrier-introduction PR (same pattern as the tag_field debt requirement). Co-Authored-By: Claude Opus 4.7 (1M context) --- .../r3-substrate-s5-coproduct-projection-carrier-worker.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md b/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md index 06bdd6a0c58..31d78898fab 100644 --- a/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md +++ b/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md @@ -29,7 +29,7 @@ type CoproductProjection { These were flagged as STOP-and-PING in canvas; Director pre-ratified the dispositions so worker can proceed without re-pinging unless evidence forces escalation. -1. **`DeclarationRef = String` alias at `dsl/std/serialization.dag:16`** — **Disposition: (b) accept alias for this slice + debt note.** Promoting `DeclarationRef` to structural typed shape mid-slice is cascade scope creep per `feedback_construction_over_ratchets`. Document the soft-typed nominal handle in `CoproductProjection` carrier comments; add a debt-paydown row pointing at future structural promotion of `DeclarationRef`. **Re-escalate to Mgr only if** worker surfaces evidence the alias actively breaks something same-slice (e.g., Anthropic #1702 wiring triggers a string-identity bridge per `feedback_opaque_strings_attract_heuristics`). +1. **`DeclarationRef = String` alias at `dsl/std/serialization.dag:16`** — **Disposition: (b) accept alias for this slice + debt note with named dissolution trigger.** Promoting `DeclarationRef` to structural typed shape mid-slice is cascade scope creep per `feedback_construction_over_ratchets`. Document the soft-typed nominal handle in `CoproductProjection` carrier comments. **Dissolution trigger** (binding per P5 scaffold/debt discipline): promote `DeclarationRef` from `String` alias to structural typed shape (e.g., `(module: ModuleId, name: DeclarationName)` record, or `DeclarationId` with bootstrap-module witness) when **EITHER (a)** audit-row #14 (`declaration_name_preference_rank` / `declaration_by_name` rank-table at `bridge-retirement-audit-sourcespan-family.md:93` row 14) closes — i.e., dsl/std ↔ src/v3/std module convergence makes name-keyed identity unambiguous and the substrate has structural module identity available; **OR (b)** any `DeclarationRef`-typed consumer surfaces a string-identity bridge per `feedback_opaque_strings_attract_heuristics` (e.g., heuristic patching on the alias' string contents, naming-convention dispatch, suffix/prefix matching). Worker MUST add a debt-paydown row to authoritative debt ledger naming `DeclarationRef` + this trigger before merging carrier-introduction PR. **Re-escalate to Mgr** if neither (a) nor (b) is satisfied but evidence emerges mid-slice that the alias actively breaks something same-slice (e.g., Anthropic #1702 wiring forces a string-identity dispatch). 2. **`FieldRef` does not exist at HEAD; only `InputFieldRef` at `services.dag:34`** — **Disposition: grep-decide between two structural patterns.** Worker greps `services.dag` + adjacent surface for `InputFieldRef` consumers BEFORE deciding (per `feedback_emitter_workaround_is_gap_symptom` + `feedback_audit_adjacent_authority_first`): - If `InputFieldRef` carries input-specific structural context → introduce `FieldRef` as the general carrier; treat `InputFieldRef` as specialization (compose, not parallel-author). From 8a1f5c738cb6f5e3bbad1c276d322eba9ccfe803 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 06:24:29 +0000 Subject: [PATCH 13/27] =?UTF-8?q?docs:=20complete=20Q-Reification=20stale-?= =?UTF-8?q?cite=20sweep=20=E2=80=94=20e6-g1a=20brief=20:169=20+=20Q-PAFS?= =?UTF-8?q?=20row?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169 still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate carrier lands. Fixed: 1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring work (lens fold consuming Dag via .dag body authority through Evaluator), NOT for a carrier-introduction. 2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after Q-Reification + ReflectedProgram" — contradicted my new Q-Reification row in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A); remaining hold = Branch B η non-vacuity only. Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md contains 4 stale cites but is not modified in this PR; stale-on-main can be swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens worker brief, not the feasibility probe per Q-PAFS Path A acceptance). Co-Authored-By: Claude Opus 4.7 (1M context) --- docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md | 7 +++++-- docs/r3-program-plan.md | 2 +- 2 files changed, 6 insertions(+), 3 deletions(-) diff --git a/docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md b/docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md index b045265b467..27c16318ac7 100644 --- a/docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md +++ b/docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md @@ -166,5 +166,8 @@ format/check command normally required for touched files. Verification V1 remains cascade-routed separately: if TC1 can use this argument-opaque representative, V1 may pair with E3 in narrow form; if TC1 -requires real lens-over-`Dag` folding, V1 waits for Q-Reification and the -carrier landing. +requires real lens-over-`Dag` folding (consuming `Dag` via `.dag` body +authority through Evaluator per Q-Reification Option A ratified 2026-05-07 +[#2096](https://github.com/gunb-ai/gunbc/pull/2096); `Dag` IS the reflected +program — no separate carrier lands), V1 waits for that consumer-wiring work +to land, NOT for a carrier-introduction. diff --git a/docs/r3-program-plan.md b/docs/r3-program-plan.md index 06dfef50c14..7ef8d73b471 100644 --- a/docs/r3-program-plan.md +++ b/docs/r3-program-plan.md @@ -951,7 +951,7 @@ Substrate canvas + plan-poke-hole both folded in. Key absorptions: | ID | Question | PM recommendation (applied as default) | Status | |---|---|---|---| -| Q-PAFS | Which Pattern-A (DimensionReport-typed family) first executable slice (TC1 vs RustDagIsomorphism vs other) | **TC1 first slice = static representative via E6-G1.a (Path A)** — `docs/briefs/r3-v-tc1-eta-equivalence-deeper-analysis.md`: **DESIGN → ACCEPTED** (2026-05-06): Path B (TC1 generic G1.b / X1.b) **deferred**; Path C (RustDagIsomorphism before TC1) **not** under Q-PAFS default (Director reorder only). PM default and Verification Mgr engineering choice **align on Path A**. **ACCEPTED 2026-05-06** per Brian directive ("approved path A countersign"). **Canonical row authority:** the **committed text of this §10.3 table** at repo `HEAD` (PR #1824 is the **merge record** for the countersign landing on `main`, not a second source of truth). | **ACCEPTED 2026-05-06 (Path A)** — **Policy** locked (TC1 first via E6-G1.a static representative). **Implementation supersession 2026-05-06:** TC1 V1 (`tc1_eta_equivalence_executable`) **HELD** — Director [#828](https://github.com/gunb-ai/gunbc/issues/828) **η non-vacuity (Branch B)** + **Q-Reification** STOP; V1 **unpairs** from Evaluator E3 Option 3 **argument-opaque** slice (vacuous vs `docs/briefs/r3-v-tc1-eta-equivalence-deeper-analysis.md` §What TC1 Asserts). Resume after Q-Reification + **ReflectedProgram\** (non-vacuous fold) or explicit §1.8 plumbing-only milestone (**not** ratified). Evaluator E3 narrow mechanism may proceed **without** TC1 pairing. Worker elaboration (non-authoritative): `docs/briefs/r3-v-pattern-a-tc1-v1-worker.md`. Path B / Path C deferred-not-blocked. | +| Q-PAFS | Which Pattern-A (DimensionReport-typed family) first executable slice (TC1 vs RustDagIsomorphism vs other) | **TC1 first slice = static representative via E6-G1.a (Path A)** — `docs/briefs/r3-v-tc1-eta-equivalence-deeper-analysis.md`: **DESIGN → ACCEPTED** (2026-05-06): Path B (TC1 generic G1.b / X1.b) **deferred**; Path C (RustDagIsomorphism before TC1) **not** under Q-PAFS default (Director reorder only). PM default and Verification Mgr engineering choice **align on Path A**. **ACCEPTED 2026-05-06** per Brian directive ("approved path A countersign"). **Canonical row authority:** the **committed text of this §10.3 table** at repo `HEAD` (PR #1824 is the **merge record** for the countersign landing on `main`, not a second source of truth). | **ACCEPTED 2026-05-06 (Path A)** — **Policy** locked (TC1 first via E6-G1.a static representative). **Implementation supersession 2026-05-06:** TC1 V1 (`tc1_eta_equivalence_executable`) **HELD** — Director [#828](https://github.com/gunb-ai/gunbc/issues/828) **η non-vacuity (Branch B)** + **Q-Reification** STOP **CLEARED 2026-05-07 (Option A: `Dag` IS the reflected program — see Q-Reification row below)**; remaining hold = **Director η non-vacuity (Branch B)** only. V1 **unpairs** from Evaluator E3 Option 3 **argument-opaque** slice (vacuous vs `docs/briefs/r3-v-tc1-eta-equivalence-deeper-analysis.md` §What TC1 Asserts). Resume after lens fold consumes `Dag` via `.dag` body authority through Evaluator (real lens-over-Dag fold, non-vacuous η obligation; consumer-wiring work, NOT carrier-introduction) or explicit §1.8 plumbing-only milestone (**not** ratified). Evaluator E3 narrow mechanism may proceed **without** TC1 pairing. Worker elaboration (non-authoritative): `docs/briefs/r3-v-pattern-a-tc1-v1-worker.md`. Path B / Path C deferred-not-blocked. | | Q-NYI-Accounting | NYI claim coverage/completeness accounting | Mark NYI incomplete in aggregation reporting; ratchet to executable per evaluator-slice landing | RATIFIED-by-default | | Q-Std-Carrier-Phasing | Rust std-carrier phasing (Option/Cardinal/HigherOrderMethodSpec/allocator-hasher) | Phase 1 = default-only/default-instance; later phases as separate Substrate slices post-Phase-1 | RATIFIED-by-default | | Q-Drift-Reconcile | Drift items routing (#1638, #1499, declaration_by_name) | Single Debt-Paydown worker reconciles all three → one PR closing rows in ledger + ROADMAP | RATIFIED-by-default | From 5fc9221c29954544ce9f2a121a06a49cf0ad3049 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 06:29:20 +0000 Subject: [PATCH 14/27] =?UTF-8?q?docs(briefs):=20S5=20=E2=80=94=20fix=20In?= =?UTF-8?q?putFieldRef=20mis-read;=20reframe=20observations=20#2=20+=20#3?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36. The text actually says "No separate InputFieldRef carrier is introduced here, since ParamToken.name already carries the same shape and adding a wrapper would duplicate without strengthening the structural invariant" — i.e., InputFieldRef does NOT exist; the comment REJECTS the wrapper. Fixes: 1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD; services.dag:28-36 precedent argues against wrapper unless it strengthens structural invariant. New (a)/(b) STOP-and-PING: (a) follow services.dag precedent — wire_tag_field: String + key invariant on wire_tag_values + fixture-load fail-closed check; (b) introduce typed FieldRef — must justify per "duplicate without strengthening" test. 2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef} pending observation #2 resolution. 3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is conditional on path (b); under path (a) no asymmetry exists. Trigger correspondingly conditional. Removed stale "InputFieldRef classified" trigger clause. Co-Authored-By: Claude Opus 4.7 (1M context) --- ...ate-s5-coproduct-projection-carrier-worker.md | 16 ++++++++++------ 1 file changed, 10 insertions(+), 6 deletions(-) diff --git a/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md b/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md index 31d78898fab..412a80a58a0 100644 --- a/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md +++ b/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md @@ -18,7 +18,7 @@ Substrate-fact-introduction (P1 procedure): typed REST response projection carri type CoproductProjection { declaration: DeclarationRef variant_field_projections: Map - wire_tag_field: FieldRef // which field carries the wire-tag discriminator + wire_tag_field: {String|FieldRef} // shape decided by substrate observation #2 STOP-and-PING; see disposition wire_tag_values: Map } ``` @@ -31,12 +31,16 @@ These were flagged as STOP-and-PING in canvas; Director pre-ratified the disposi 1. **`DeclarationRef = String` alias at `dsl/std/serialization.dag:16`** — **Disposition: (b) accept alias for this slice + debt note with named dissolution trigger.** Promoting `DeclarationRef` to structural typed shape mid-slice is cascade scope creep per `feedback_construction_over_ratchets`. Document the soft-typed nominal handle in `CoproductProjection` carrier comments. **Dissolution trigger** (binding per P5 scaffold/debt discipline): promote `DeclarationRef` from `String` alias to structural typed shape (e.g., `(module: ModuleId, name: DeclarationName)` record, or `DeclarationId` with bootstrap-module witness) when **EITHER (a)** audit-row #14 (`declaration_name_preference_rank` / `declaration_by_name` rank-table at `bridge-retirement-audit-sourcespan-family.md:93` row 14) closes — i.e., dsl/std ↔ src/v3/std module convergence makes name-keyed identity unambiguous and the substrate has structural module identity available; **OR (b)** any `DeclarationRef`-typed consumer surfaces a string-identity bridge per `feedback_opaque_strings_attract_heuristics` (e.g., heuristic patching on the alias' string contents, naming-convention dispatch, suffix/prefix matching). Worker MUST add a debt-paydown row to authoritative debt ledger naming `DeclarationRef` + this trigger before merging carrier-introduction PR. **Re-escalate to Mgr** if neither (a) nor (b) is satisfied but evidence emerges mid-slice that the alias actively breaks something same-slice (e.g., Anthropic #1702 wiring forces a string-identity dispatch). -2. **`FieldRef` does not exist at HEAD; only `InputFieldRef` at `services.dag:34`** — **Disposition: grep-decide between two structural patterns.** Worker greps `services.dag` + adjacent surface for `InputFieldRef` consumers BEFORE deciding (per `feedback_emitter_workaround_is_gap_symptom` + `feedback_audit_adjacent_authority_first`): - - If `InputFieldRef` carries input-specific structural context → introduce `FieldRef` as the general carrier; treat `InputFieldRef` as specialization (compose, not parallel-author). - - If `InputFieldRef` is just narrowly-named for an input use-case → rename to `FieldRef` (per `feedback_naming_is_aliasing` — rename is structural-cheap). - - **Do NOT** manufacture a parallel-authority second `FieldRef`. +2. **No `FieldRef`-shaped carrier exists at HEAD** — corrected per codex BLOCKING at PR #2079. Earlier framing referenced "`InputFieldRef` at `services.dag:34`" — that line is a **comment explicitly REJECTING** the wrapper: *"No separate `InputFieldRef` carrier is introduced here, since `ParamToken.name` already carries the same shape and adding a wrapper would duplicate without strengthening the structural invariant"* (`src/v3/std/services.dag:28-36`). The services.dag precedent: parameter-input identity lives in `Map`'s key invariant + `ParamToken.name`; no parallel typed-handle wrapper. -3. **`InternallyTaggedObject.tag_field: String` asymmetry at `dsl/std/serialization.dag:49`** — **Disposition: typed introduction here + debt note for future migration with named dissolution trigger.** Per `feedback_parallel_representation_debt`, the typed/string asymmetry is recorded as known shape mismatch. **Dissolution trigger** (binding per P5 scaffold/debt discipline): when **(a)** `FieldRef` exists as a typed top-level carrier in the substrate AND **(b)** `InputFieldRef` (currently at `services.dag:34`) has been classified — either retained as input-scoped specialization or renamed to general `FieldRef` per substrate observation #2 above — THEN migrate `InternallyTaggedObject.tag_field: String` → `InternallyTaggedObject.tag_field: FieldRef` in a follow-on Substrate hygiene PR (analogous to Q2 `result_port` canonical rename per Substrate Mgr standing dispatch authority). Worker MUST add a debt-paydown row to `docs/debt/r3-debt-paydown-ledger-2026-05-02.md` (or current authoritative debt ledger at HEAD) naming this carrier + dissolution trigger before merging the carrier-introduction PR. Do NOT fix in same slice unless evidence shows the asymmetry actively blocks a downstream consumer. + **Disposition (revised)**: `CoproductProjection.wire_tag_field` faces the same shape question — does it need a typed wrapper, or does the structural invariant already exist elsewhere? Two paths, **STOP-and-PING the Mgr** before choosing: + - **(a) Follow services.dag precedent (no wrapper)**: `wire_tag_field: String`, with structural identity carried by `Map` key invariant on `wire_tag_values` + a fail-closed check at fixture load that `wire_tag_field` names a real field on the coproduct's variant payloads. Adds NO new carrier; aligns with `feedback_construction_over_ratchets`. Asymmetry with `WireTagValue` (typed leaf, binding per Director constraint #2) is acceptable — values and field-handles are distinct concerns. + - **(b) Introduce typed `FieldRef`**: new top-level structural carrier; ergonomic when consumers need to compose field-identity across coproduct + record + tagged-object surfaces. Stronger structural invariant than (a) but introduces a new carrier — must justify per services.dag precedent's "duplicate without strengthening" test. + - **Do NOT** manufacture an `InputFieldRef`-shaped wrapper (services.dag:28-36 explicitly rejected that shape). + +3. **`InternallyTaggedObject.tag_field: String` asymmetry at `dsl/std/serialization.dag:49`** — **Disposition: conditional debt with named dissolution trigger.** Asymmetry only exists if substrate observation #2 resolves to **path (b)** (introduce typed `FieldRef`). If observation #2 resolves to **path (a)** (no wrapper, follow services.dag precedent), then `wire_tag_field: String` matches `InternallyTaggedObject.tag_field: String` — no asymmetry, no debt. Per `feedback_parallel_representation_debt`, recorded as shape-question rather than known mismatch. + + **Dissolution trigger** (binding per P5 scaffold/debt discipline; applies ONLY if observation #2 path (b) is chosen): when **(a)** typed `FieldRef` exists as top-level carrier (introduced via observation #2 path (b)) AND **(b)** evidence emerges that a downstream consumer benefits from typed field-identity in `InternallyTaggedObject` (per `feedback_emitter_workaround_is_gap_symptom`), THEN migrate `InternallyTaggedObject.tag_field: String` → `FieldRef` in a follow-on Substrate hygiene PR. Worker MUST add a debt-paydown row to authoritative debt ledger at HEAD naming this carrier + trigger before merging the carrier-introduction PR. Do NOT fix in same slice unless evidence shows the asymmetry actively blocks a downstream consumer. ## Acceptance gates (same-slice, all must pass) From 598776f4f8448de4236b52c126b813b472b67b0b Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 06:30:27 +0000 Subject: [PATCH 15/27] =?UTF-8?q?docs(briefs):=20S5=20=E2=80=94=20consolid?= =?UTF-8?q?ate=20split=20per-variant=20maps=20into=20single=20keyed=20entr?= =?UTF-8?q?y?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split per-variant data across two parallel maps (variant_field_projections + wire_tag_values), admitting illegal states where keysets drift (P2 boundary discipline / illegal-states-unrepresentable). Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value } as the per-variant keyed value; CoproductProjection.variant_projections becomes Map. Single keyed authority per variant. Director's binding constraint #2 enumerated the two fields separately but said "refine in implementation as ergonomics demand" — consolidation preserves the substantive constraints (typed WireTagValue leaf, structural per-variant projection) while enforcing keyset alignment by carrier shape. Empty-payload variants encoded via FieldProjection::Empty constructor (or analog), not via map-absence. Co-Authored-By: Claude Opus 4.7 (1M context) --- ...trate-s5-coproduct-projection-carrier-worker.md | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) diff --git a/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md b/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md index 412a80a58a0..f3766354cc6 100644 --- a/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md +++ b/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md @@ -15,14 +15,20 @@ Substrate-fact-introduction (P1 procedure): typed REST response projection carri **Initial shape** (refine in implementation as ergonomics demand): ```dag +type CoproductVariantProjection { + field_projection: FieldProjection // payload field projection for this variant + wire_tag_value: WireTagValue // typed wire-tag for this variant +} + type CoproductProjection { - declaration: DeclarationRef - variant_field_projections: Map - wire_tag_field: {String|FieldRef} // shape decided by substrate observation #2 STOP-and-PING; see disposition - wire_tag_values: Map + declaration: DeclarationRef + wire_tag_field: {String|FieldRef} // shape decided by substrate observation #2 STOP-and-PING; see disposition + variant_projections: Map } ``` +**Single-keyed-fact discipline (P2 boundary)**: per-variant payload + tag-value are one keyed fact, not two parallel maps. Director's binding constraint #2 originally enumerated them as separate fields ("refine in implementation as ergonomics demand"); the consolidated `CoproductVariantProjection` shape preserves the substantive constraints (typed `WireTagValue` leaf, structural per-variant projection) while making illegal states unrepresentable — a variant cannot have a field projection without a wire-tag value or vice versa. If "variant has no payload fields" is legitimate (e.g., Anthropic's empty-payload variants), encode that explicitly via a `FieldProjection::Empty` constructor or analog inside `CoproductVariantProjection.field_projection` rather than as absence from one map. + `WireTagValue` MUST be a typed leaf (sum type or named record), **not** `String`. If Anthropic + REST both serialize as string at the wire boundary, encode the typed-on-our-side / serialized-at-emit pattern: `WireTagValue` stays typed in substrate; serialization adapter handles `String <-> WireTagValue` at the wire boundary. ### Substrate observations — Director pre-ratified dispositions (gunbc#828 #issuecomment-4394416049) From 4656801fefa3bf1178799023a685b5a2be957854 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 06:43:18 +0000 Subject: [PATCH 16/27] =?UTF-8?q?docs(briefs):=20S5=20=E2=80=94=20fix=20st?= =?UTF-8?q?ale=20split-map=20vocab=20in=20path=20(a)=20+=20scope=20STOP-an?= =?UTF-8?q?d-PING=20umbrella?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings. 1. Path (a) at line 43 still referenced "Map key invariant on wire_tag_values" — that's the superseded split-map vocab; the consolidated shape is Map on variant_projections. Path (a) now references the consolidated map; per-variant WireTagValue lives inside CoproductVariantProjection. 2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified, proceed without re-pinging" — but observation #2 was re-opened after the codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory. Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened STOP-and-PING — worker MUST escalate before choosing path (a) vs (b). Co-Authored-By: Claude Opus 4.7 (1M context) --- .../r3-substrate-s5-coproduct-projection-carrier-worker.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md b/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md index f3766354cc6..8bebfb70899 100644 --- a/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md +++ b/docs/briefs/r3-substrate-s5-coproduct-projection-carrier-worker.md @@ -33,14 +33,14 @@ type CoproductProjection { ### Substrate observations — Director pre-ratified dispositions (gunbc#828 #issuecomment-4394416049) -These were flagged as STOP-and-PING in canvas; Director pre-ratified the dispositions so worker can proceed without re-pinging unless evidence forces escalation. +**Pre-ratification scope** — Director pre-ratified observations **#1 (DeclarationRef alias)** and **#3 (tag_field asymmetry conditional)** at gunbc#828 #issuecomment-4394416049; worker proceeds on those without re-pinging unless evidence forces escalation. **Observation #2 was re-opened** after codex BLOCKING at gunbc#2079 corrected an `InputFieldRef` mis-read; #2's `wire_tag_field` shape decision (path (a) vs (b)) **remains an open STOP-and-PING** — worker MUST escalate to Mgr before choosing, NOT proceed silently. 1. **`DeclarationRef = String` alias at `dsl/std/serialization.dag:16`** — **Disposition: (b) accept alias for this slice + debt note with named dissolution trigger.** Promoting `DeclarationRef` to structural typed shape mid-slice is cascade scope creep per `feedback_construction_over_ratchets`. Document the soft-typed nominal handle in `CoproductProjection` carrier comments. **Dissolution trigger** (binding per P5 scaffold/debt discipline): promote `DeclarationRef` from `String` alias to structural typed shape (e.g., `(module: ModuleId, name: DeclarationName)` record, or `DeclarationId` with bootstrap-module witness) when **EITHER (a)** audit-row #14 (`declaration_name_preference_rank` / `declaration_by_name` rank-table at `bridge-retirement-audit-sourcespan-family.md:93` row 14) closes — i.e., dsl/std ↔ src/v3/std module convergence makes name-keyed identity unambiguous and the substrate has structural module identity available; **OR (b)** any `DeclarationRef`-typed consumer surfaces a string-identity bridge per `feedback_opaque_strings_attract_heuristics` (e.g., heuristic patching on the alias' string contents, naming-convention dispatch, suffix/prefix matching). Worker MUST add a debt-paydown row to authoritative debt ledger naming `DeclarationRef` + this trigger before merging carrier-introduction PR. **Re-escalate to Mgr** if neither (a) nor (b) is satisfied but evidence emerges mid-slice that the alias actively breaks something same-slice (e.g., Anthropic #1702 wiring forces a string-identity dispatch). 2. **No `FieldRef`-shaped carrier exists at HEAD** — corrected per codex BLOCKING at PR #2079. Earlier framing referenced "`InputFieldRef` at `services.dag:34`" — that line is a **comment explicitly REJECTING** the wrapper: *"No separate `InputFieldRef` carrier is introduced here, since `ParamToken.name` already carries the same shape and adding a wrapper would duplicate without strengthening the structural invariant"* (`src/v3/std/services.dag:28-36`). The services.dag precedent: parameter-input identity lives in `Map`'s key invariant + `ParamToken.name`; no parallel typed-handle wrapper. **Disposition (revised)**: `CoproductProjection.wire_tag_field` faces the same shape question — does it need a typed wrapper, or does the structural invariant already exist elsewhere? Two paths, **STOP-and-PING the Mgr** before choosing: - - **(a) Follow services.dag precedent (no wrapper)**: `wire_tag_field: String`, with structural identity carried by `Map` key invariant on `wire_tag_values` + a fail-closed check at fixture load that `wire_tag_field` names a real field on the coproduct's variant payloads. Adds NO new carrier; aligns with `feedback_construction_over_ratchets`. Asymmetry with `WireTagValue` (typed leaf, binding per Director constraint #2) is acceptable — values and field-handles are distinct concerns. + - **(a) Follow services.dag precedent (no wrapper)**: `wire_tag_field: String`, with structural identity carried by the consolidated `Map` key invariant on `variant_projections` (each variant's `wire_tag_value` is the per-variant typed authority) + a fail-closed check at fixture load that the `String` value names a real field on the coproduct's variant payloads. Adds NO new carrier; aligns with `feedback_construction_over_ratchets`. Asymmetry with `WireTagValue` (typed leaf, binding per Director constraint #2) is acceptable — values and field-handles are distinct concerns. - **(b) Introduce typed `FieldRef`**: new top-level structural carrier; ergonomic when consumers need to compose field-identity across coproduct + record + tagged-object surfaces. Stronger structural invariant than (a) but introduces a new carrier — must justify per services.dag precedent's "duplicate without strengthening" test. - **Do NOT** manufacture an `InputFieldRef`-shaped wrapper (services.dag:28-36 explicitly rejected that shape). From aac5b3b4a4cc2a0702faed66d07a59f51dd044a5 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 07:24:31 +0000 Subject: [PATCH 17/27] =?UTF-8?q?docs(briefs):=20descent=5Fexecution=5Fpro?= =?UTF-8?q?of=20canvas=20=E2=80=94=204-residual=20coproduct-dissolution=20?= =?UTF-8?q?audit?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Director ratified split disposition at gunbc#828 #issuecomment-4394696074: descent_execution_proof STANDS ALONE (consumer-side termination-contract substrate function with fail-closed residual enumeration; folding into T-E-P-Producer-Broadening explicitly rejected — different concern axis). Canvas surfaces 3 carrier-shape options for the residual enumeration per Director's coproduct-dissolution audit suggestion: α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown | Incomplete | NonStrict) β: 3-axis dimensional product (presence × completeness × strictness) γ (recommended): reuse DescentEvidence at termination.dag:14-17 for "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant + separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional folding while honoring services.dag "no parallel wrapper" precedent. Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally. Co-Authored-By: Claude Opus 4.7 (1M context) --- ...ubstrate-descent-execution-proof-canvas.md | 108 ++++++++++++++++++ 1 file changed, 108 insertions(+) create mode 100644 docs/briefs/r3-substrate-descent-execution-proof-canvas.md diff --git a/docs/briefs/r3-substrate-descent-execution-proof-canvas.md b/docs/briefs/r3-substrate-descent-execution-proof-canvas.md new file mode 100644 index 00000000000..b97c2bd3d72 --- /dev/null +++ b/docs/briefs/r3-substrate-descent-execution-proof-canvas.md @@ -0,0 +1,108 @@ +# Canvas — Substrate `descent_execution_proof` carrier (P1 substrate-fact-introduction) + +**Parent**: gunbc#1939 (Substrate Mgr lane); will be parented under a PM-authored work-item under #1939 post-ratification. +**Authority**: `docs/r3-program-plan.md` §10.3 row Q-EVAL-Descent-Termination-Contract (line 966); Director ratification of split disposition at gunbc#828 #issuecomment-4394696074 (descent_execution_proof STANDS ALONE; folds-into-T-E-P explicitly rejected). +**Closure predicate**: Evaluator E2 descent termination contract consumer (#1971); fail-closed residual enumeration is the load-bearing structural fact. +**Status**: **canvas — Director-tier ratification needed on residual enumeration shape before worker brief authoring**. + +## Scope + +Substrate carrier for executor-side termination-contract verification: + +``` +descent_execution_proof(&Dag, ClusterId, PortId) + -> Result +``` + +Per §10.3 row 966 the residual enumeration was provisionally named `Missing | Unknown | Incomplete | NonStrict`. The shape question is: **what is the minimum-irreducible variant set for `DescentResidual`?** + +## Adjacent substrate (grep-verified at HEAD) + +`src/v3/std/termination.dag:14-17` already defines: + +```dag +type DescentEvidence + = Strict + | NonIncreasing + | DescentUnknown +``` + +with `BoundedLattice` ordering `DescentUnknown < NonIncreasing < Strict` (top = `Strict`, bottom = `DescentUnknown` per fail-closed discipline). `merge_evidence` / `join_evidence` are conservative-meet / optimistic-join. + +So the residual question must reconcile with the existing 3-variant evidence type. **`Unknown` in the residual enumeration ≡ `DescentEvidence::DescentUnknown`**; reusing the existing carrier is the structural-cheap default unless a distinction emerges. + +## Carrier-shape options for the residual enumeration + +### Option α — 4-variant coproduct (as named in §10.3 row 966) + +```dag +type DescentResidual + = Missing // no DescentEvidence carrier present at the call site + | Unknown // DescentEvidence::DescentUnknown surfaced + | Incomplete // per-path evidence exists but some paths uncovered + | NonStrict // evidence is NonIncreasing (not Strict) +``` + +**Pro**: matches §10.3 row 966 verbatim; explicit named cases; readable at the consumer. +**Con**: `Missing` and `Unknown` may collapse — both are "evidence-absent" with different cardinalities (no carrier vs `DescentUnknown` carrier). Per `feedback_coproduct_dissolution`, this is the kind of variant pair that should ratchet downward unless there's a load-bearing distinction. Same for `Incomplete` vs `NonStrict` — both are "evidence-present-but-insufficient", differing on which axis (path-coverage vs strictness). + +### Option β — Dimensional product report + +```dag +type DescentResidualReport { + presence: EvidencePresence // CarrierPresent | CarrierAbsent + completeness: PathCoverage // AllPathsCovered | SomePathsUncovered + strictness: StrictnessVerdict // Strict | NonIncreasing | NotApplicable +} +``` + +Decomposes the 4-coproduct into 3 orthogonal axes; the executor reports per-axis verdict; the "fail" condition is any non-top axis. + +**Pro**: maximum structural decomposition per `feedback_coproduct_dissolution`; eliminates illegal-state question of whether `Incomplete` and `NonStrict` are mutually exclusive (the answer: no — a proof can be both); per-axis independent reasoning. +**Con**: heavier shape; requires defining 3 sub-types (`EvidencePresence`, `PathCoverage`, `StrictnessVerdict`) instead of 1; `StrictnessVerdict::NotApplicable` admits illegal state when carrier is absent (presence=CarrierAbsent + strictness=Strict shouldn't be representable). If the 3 axes don't actually compose orthogonally (i.e., some combinations are nonsensical), product shape is wrong. + +### Option γ — Reuse `DescentEvidence` for "absent/unknown"; 2 additional residuals + +```dag +type DescentResidual + = EvidenceUnknown(DescentEvidence) // wraps DescentUnknown (or NonIncreasing reported as not-strict) + | EvidenceIncomplete // multi-path partial coverage +``` + +3-variant collapse of α: `Missing` and `Unknown` fold into a single `EvidenceUnknown(DescentEvidence)` payload (the `Missing` case is `DescentUnknown` synthesized by the executor when no carrier is present); `NonStrict` folds into `EvidenceUnknown(NonIncreasing)` since the existing lattice already distinguishes `NonIncreasing` from `Strict`; `Incomplete` remains separate because path-coverage IS structurally distinct from per-evidence strictness. + +**Pro**: reuses `DescentEvidence` carrier per `feedback_audit_adjacent_authority_first`; ratchets variant count from 4 → 2 via dimensional folding; `EvidenceUnknown(Strict)` is unrepresentable by construction (Strict isn't a residual). +**Con**: payload-typed variant is heavier than bare-name variant; consumers must pattern-match on the payload to recover the original 4-case story; "Strict" appearing under `EvidenceUnknown` requires an inhabited-only-by-non-Strict refinement type or a runtime check (mild illegal-state risk). + +## Mgr-tier recommendation + +Provisional **γ**: ratchets the variant count via dimensional folding (per Director's coproduct-dissolution audit suggestion) while reusing the existing `DescentEvidence` carrier (services.dag-style "no parallel wrapper" precedent). The `Strict`-shouldn't-appear-here illegal-state risk is mild and addressable via either a refinement type (`DescentEvidence \ Strict`) or a fixture-load fail-closed check. + +If γ's payload-pattern-match cost is unacceptable for consumer ergonomics, **α** with explicit Mgr-acknowledgment that `Missing` ≡ `Unknown` (rather than fold via constructor injection) is the second-best — names the cases verbatim from §10.3 at the cost of one redundant variant. + +**β rejected** unless the 3 axes provably compose orthogonally — risk of admitting illegal states (carrier-absent + strictness=Strict) is real and would require additional refinement-shape work. + +## Director ratification ask + +1. **Pick α / β / γ** (or surface a fourth option). Provisional Mgr recommendation: **γ**. +2. Confirm the existing `DescentEvidence` 3-variant lattice at `termination.dag:14-17` is the authoritative starting point — i.e., the residual carrier composes with it rather than re-inventing it. +3. Confirm the typed signature `descent_execution_proof(&Dag, ClusterId, PortId) -> Result` from §10.3 row 966 is verbatim-binding, OR ratify a refinement (e.g., `&Dag` may need to be `&Dag` + module witness; `ClusterId` + `PortId` are existing Substrate types — verify via grep at worker brief time). + +## On ratification — worker brief scope + +Will author execution brief covering: +- `DescentResidual` carrier in `src/v3/std/termination.dag` (or sibling file if cleaner) per chosen option +- `DescentExecutionProof` carrier shape (witness payload — likely a mini-DAG or per-path evidence map) +- `descent_execution_proof()` substrate function signature in DSL with fail-closed body shape +- Acceptance: §1.8 gates per row 966 closure predicate; bootstrap regen + clippy + workspace tests green +- Cross-Mgr handoff: Evaluator (#1971 / crisp-bat-13) consumes carrier; Q-EVAL-Descent-Termination-Contract row 966 advances to `CONSUMER_LANDED` + +## Worker pin (Mgr disposition) + +**quick-koi-190** — already authorized through quick-crab per §10.3 row 966 ("quick-koi-190 implementation already authorized through quick-crab"); also currently on T-E-P P1 work which is conceptually adjacent (DescentEvidence producer broadening). Final pin at dispatch. + +## Auto-spawn caveat + +Per Director note 2026-05-07: worker auto-spawn from Mgr-context is bug-affected; HOLD dispatch on this canvas's worker brief until auto-spawn fix lands per L-sized-not-low-risk threshold. + +— Authored by warm-wolf-698 (Substrate Mgr) 2026-05-07 post-#2079 merge per Director serial-cadence direction at gunbc#828 #issuecomment-4394696074. Coproduct-dissolution audit per Director's micro-suggestion in same message. From 622361c2c7380be504593f16d890d2b8d024a962 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 07:28:44 +0000 Subject: [PATCH 18/27] =?UTF-8?q?docs(briefs):=20SourceSpan=20brief=20Row?= =?UTF-8?q?=20#6=20=E2=80=94=20derive=20from=20bootstrap=5Fauthority=20map?= =?UTF-8?q?,=20no=20new=20enum=20variant?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit codex BLOCKING (post-merge of #2079, on commit 85ceb85a — same brief is now on main): my Row #6 disposition told the worker to introduce a new BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag under the existing CompilerAuthority variant. The :14-17 comment is explicit: "the path itself is the BootstrapAuthoritySet map key; variants carry no duplicate path payload" — single authority, not extension-by-variant. Fix: Row #6 now instructs worker to derive the typed key from the existing bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing CompilerAuthority classifier), refining the constructor surface if needed — NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid new-variant resolution under any path. Co-Authored-By: Claude Opus 4.7 (1M context) --- ...strate-bridge-source-span-file-participation-worker.md | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/docs/briefs/r3-substrate-bridge-source-span-file-participation-worker.md b/docs/briefs/r3-substrate-bridge-source-span-file-participation-worker.md index b4b05d79f6c..df2b25b5eae 100644 --- a/docs/briefs/r3-substrate-bridge-source-span-file-participation-worker.md +++ b/docs/briefs/r3-substrate-bridge-source-span-file-participation-worker.md @@ -45,8 +45,10 @@ Authority constants: `BOOL_TYPES_FILE` (`dsl/std/types.dag`), `PIPELINE_AUTHORIT - Diagnostic span: synthesize from `BootstrapAuthorityKey` rather than `SourceSpan::new(BOOL_TYPES_FILE, 0, 0)` — the `BootstrapAuthorityKey::new(...)` wrapper already exists at `:125`, and `DiagnosticAttribution::BootstrapAuthority` (per `:519` doc-comment) is the steady-state attribution surface (PB row 82). - **Prerequisite**: `dsl/std/types.dag` ↔ `src/v3/std/types.dag` duplicate-module convergence per ROADMAP T-P0 must NOT regress; if both hold a `Bool`, `declaration_by_name` rank still applies (audit row #14 — root blocker, **out-of-scope here**). -**Row #6 (pipeline authority)** — replace `PIPELINE_AUTHORITY_FILE` guards: -- `report_pipeline_authority_error` (`:283-292`) — drop the path-string from both `BootstrapAuthorityKey` and `SourceSpan::new`. Replace with a **`BootstrapAuthority::Pipeline` typed key** (extend the enum if needed); diagnostic span sourced from the offending stage binding's actual `SourceSpan`, not a manufactured `(file, 0, 0)`. +**Row #6 (pipeline authority)** — replace `PIPELINE_AUTHORITY_FILE` guards by deriving the typed key from the existing single-authority map: +- `src/v3/std/bootstrap_authority.dag:90` already has `"src/v3/compiler/pipeline.dag": CompilerAuthority` — `pipeline.dag` is already classified under the existing `BootstrapAuthority::CompilerAuthority` variant. **DO NOT introduce a new `BootstrapAuthority::Pipeline` variant** — that would duplicate substrate authority (the `bootstrap_authority` map at `:30` is the single authority per the file's :14-17 comment: *"the path itself is the BootstrapAuthoritySet map key; variants carry no duplicate path payload"*). +- `report_pipeline_authority_error` (`:283-292`) — drop the path-string from both `BootstrapAuthorityKey` and `SourceSpan::new`. Derive the typed key from the existing `bootstrap_authority`-map witness — i.e., `BootstrapAuthorityKey` is constructed from the `(path, BootstrapAuthority::CompilerAuthority)` row already in the data, not by extending the enum. Diagnostic span sourced from the offending stage binding's actual `SourceSpan`, not a manufactured `(file, 0, 0)`. +- If the worker finds that `BootstrapAuthorityKey::new()` constructor signature doesn't currently accept a typed-classifier argument, the right shape is to thread the `BootstrapAuthority` variant through the existing constructor (refining the constructor surface), NOT to add a new top-level enum variant. - Coordinate with PB-owned `bridge_include_str_side_channels_retired` (audit row #6 sibling) — `pipeline_authority.rs::ordered_pipeline_stages` already reads `PipelineStageBinding` structurally; the bridge is ONLY in the diagnostic-span manufacturing path. ## Acceptance @@ -61,7 +63,7 @@ Authority constants: `BOOL_TYPES_FILE` (`dsl/std/types.dag`), `PIPELINE_AUTHORIT ## STOP / PING criteria - **STOP** if removing `d.span.file == BOOL_TYPES_FILE` (anchor #1) causes `declaration_by_name("Bool")` to resolve to a different declaration (rank-table ambiguity from duplicate `Bool` in `src/v3/std/types.dag` vs `dsl/std/types.dag`). This is audit row #14 root-blocker territory — surface to Mgr; do NOT delete the rank table to "fix it". -- **STOP** if `BootstrapAuthority` enum doesn't have a `Pipeline` variant and adding one cascades into emit/diagnostic surfaces beyond bootstrap.rs. Surface scope-creep to Mgr. +- **STOP** if deriving the typed key for the pipeline diagnostic from the existing `bootstrap_authority` map (per Row #6 disposition above — `CompilerAuthority` row at `bootstrap_authority.dag:90`) cascades into emit/diagnostic surfaces beyond bootstrap.rs (e.g., `BootstrapAuthorityKey::new()` constructor refinement leaks into other call sites). Surface scope-creep to Mgr. **Do NOT** introduce a new `BootstrapAuthority::Pipeline` variant under any STOP-resolution path — that's duplicate substrate authority. - **PING** Verification Mgr (#1940 / `witty-swift-269` if active) when this lands so they can advance the ledger-zero audit (`docs/briefs/r3-v-bridge-retirement-ledger-zero-audit.md` row 1). ## Cross-Mgr handoff From e2741c4f78df26077d47640dcb42294fa566395a Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 07:33:02 +0000 Subject: [PATCH 19/27] =?UTF-8?q?docs(briefs):=20descent=5Fexecution=5Fpro?= =?UTF-8?q?of=20worker=20brief=20=E2=80=94=20=CE=B3=20ratified=20(2-varian?= =?UTF-8?q?t=20residual)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Director ratification at gunbc#828 #issuecomment-4395060514: - DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection; NonStrict folds via NonIncreasing wrap; Incomplete retained — different concern axis from evidence-lattice) - DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as authoritative composition target - Type signature from §10.3 row 966 confirmed verbatim-binding Director-asked canvas-shape verification absorbed: worker STOPs if EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound / evaluator-error-during-proof-construction); proceeds as 2-variant otherwise. 7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same PR + §10.3 row 966 row-text refresh to cite γ-disposition. Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966). Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified case-by-case if critical path blocked. Co-Authored-By: Claude Opus 4.7 (1M context) --- ...ubstrate-descent-execution-proof-worker.md | 71 +++++++++++++++++++ 1 file changed, 71 insertions(+) create mode 100644 docs/briefs/r3-substrate-descent-execution-proof-worker.md diff --git a/docs/briefs/r3-substrate-descent-execution-proof-worker.md b/docs/briefs/r3-substrate-descent-execution-proof-worker.md new file mode 100644 index 00000000000..fbbe9b8b299 --- /dev/null +++ b/docs/briefs/r3-substrate-descent-execution-proof-worker.md @@ -0,0 +1,71 @@ +# Worker brief — Substrate `descent_execution_proof` carrier (γ) + +**Sub-issue**: TBD (PM creates under #1939 post-this-brief landing; Evaluator's #1971 `Depends on:` retargets to that issue). +**Authority**: Director ratification of **option γ** at gunbc#828 #issuecomment-4395060514 (2026-05-07); supersedes the canvas at `docs/briefs/r3-substrate-descent-execution-proof-canvas.md` (canvas may be deleted after this brief lands). +**Closure predicate**: Evaluator E2 descent termination contract consumer (#1971); §10.3 row 966 row-text refresh to cite γ-disposition (2-variant residual, not 4-variant prose). + +## Scope + +Substrate-fact-introduction (P1 procedure): consumer-side typed substrate function for executor termination-contract verification. Composes with existing `DescentEvidence` lattice at `src/v3/std/termination.dag:14-17`; no parallel "absent/unknown" axis. + +## Carrier shape (binding per Director γ ratification) + +**Location**: `src/v3/std/termination.dag` (extend the existing file — `DescentEvidence` already lives there; sibling typing keeps the lattice + residual co-located). Verify-via-grep at HEAD that no near-neighbor file has prior claim. + +```dag +type DescentResidual + = EvidenceUnknown(DescentEvidence) // wraps DescentUnknown for absent-evidence; wraps NonIncreasing for not-strict + | EvidenceIncomplete // proof-construction state: per-path coverage incomplete +``` + +**Single substrate function**: + +```dag +fn descent_execution_proof( + dag: &Dag, + cluster: ClusterId, + port: PortId, +) -> Result +``` + +**`DescentExecutionProof`** payload — verify shape at implementation time. Likely a per-path evidence map keyed by branch identifier with each entry carrying `DescentEvidence::Strict` (non-Strict per-path entries surface as `EvidenceUnknown(NonIncreasing)` residual via the executor's join semantics). If a richer witness shape is needed, surface as STOP-and-PING. + +### Director-asked verification (canvas-shape time) + +**STOP-and-PING the Mgr** if `EvidenceIncomplete` decomposes into payload-variants. Worker greps the existing executor-error surface for partial-coverage / timeout / depth-bound reasons: +- If `EvidenceIncomplete` is genuinely **unit-variant** (proof construction either completes for all paths or fails wholesale on one of the existing residual reasons): ratchet stops at 2-variant — proceed with γ as ratified. +- If `EvidenceIncomplete` carries a specific reason payload (e.g., `EvidenceIncomplete { reason: TimeoutReason | DepthBoundExceeded | EvaluatorErrorDuringProofConstruction }`): surface to Mgr; canvas may need a 4-decompose-to-3 update with payload-variant. + +Per Director: "this is canvas-shape verification, not a re-ratification ask. If the worker hits substrate evidence that requires payload structure, surface as STOP-and-PING; otherwise proceed with γ as 2-variant." + +## Acceptance gates (same-slice, all must pass) + +1. **`DescentResidual` carrier landed** in `src/v3/std/termination.dag` (or chosen location post-grep) per ratified γ shape (modulo STOP-resolution on `EvidenceIncomplete` payload). +2. **`DescentExecutionProof` carrier landed** with witness payload shape (per-path evidence map or richer structure surfaced via STOP-and-PING). +3. **`descent_execution_proof()` substrate function landed** with the typed signature from §10.3 row 966 (verbatim per Director confirm). +4. **Evaluator E2 (#1971) consumes the carrier** in same-slice — proves multi-consumer composability is unnecessary for this carrier (Evaluator IS the consumer per closure predicate; carrier-with-single-consumer-as-interface anti-pattern doesn't apply because the carrier is consumer-cementing for executor termination contract). PR description names the Evaluator consumer call site. +5. **§10.3 row 966 row-text update**: ROADMAP cites γ-disposition (2-variant residual) replacing the prose `Missing | Unknown | Incomplete | NonStrict` 4-variant naming. Per Director: "ROADMAP §10.3 row 966 row text should update on Gate A landing to cite this ratification." +6. Bootstrap regen: `cargo test -p v3-compiler bootstrap_regen_fresh -- --ignored` clean. +7. Full suite: `cargo test --workspace --exclude v2-compiler-tests` green; `cargo clippy --all-targets -- -D warnings` clean. + +## STOP / PING criteria + +- **STOP** if `EvidenceIncomplete` decomposes into payload-variants per the Director-asked verification above — surface to Mgr (warm-wolf-698 / inbox #2068) before adding a payload; canvas update needed. +- **STOP** if `DescentExecutionProof` witness shape requires substantial new substrate (e.g., a fresh per-path-witness type with non-trivial bootstrap-regen impact) — surface scope-creep. +- **STOP** if §10.3 row 966's verbatim signature requires refinement at implementation time (`&Dag` may need module witness; `ClusterId` / `PortId` are existing Substrate types — verify via grep at brief-execution time; surface if drift). +- **PING** Evaluator Mgr (#2065 / `crisp-bat-13`) at PR-open time so they can retarget #1971 `Depends on:` to the carrier work-item AND begin consumer wiring against the same PR. + +## Cross-Mgr coordination + +- **Evaluator Mgr (#2065 / crisp-bat-13)**: same-slice consumer (E2 `descent_execution_proof` consumer at #1971). PING at PR-open; coordinate consumer wiring in same PR per acceptance gate #4. +- **Verification Mgr (#2075 / wise-bear-525)**: standing-program ratchet authoring is Verification's concern; no specific same-slice handoff expected unless ledger row needs to advance. + +## Worker pin (Mgr disposition) + +**quick-koi-190** — pre-authorized per §10.3 row 966 ("quick-koi-190 implementation already authorized through quick-crab"); also conceptually adjacent to T-E-P P1 work (DescentEvidence producer broadening) which quick-koi-190 has been on. Final pin at dispatch. + +## Auto-spawn caveat + +Per Director note 2026-05-07 + ratification at #4395060514: worker auto-spawn from Mgr-context is bug-affected (ctrl#217); HOLD dispatch on this brief until auto-spawn fix lands per L-sized-not-low-risk threshold, OR escalate via surgical-recreate path if Pattern A cascade or another critical path is blocked. Director ratifies surgical-recreate case-by-case. + +— Authored by warm-wolf-698 (Substrate Mgr) 2026-05-07 per Director γ-ratification at gunbc#828 #issuecomment-4395060514. From 0a0491cc84a5e6384a02bd0e03475c9eafb29723 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 03:43:04 -0400 Subject: [PATCH 20/27] =?UTF-8?q?WIP:=20R3=20Substrate=20Mgr=20=E2=80=94?= =?UTF-8?q?=20lane=20through=20R3=20close?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- ...ubstrate-descent-execution-proof-canvas.md | 108 ------------------ 1 file changed, 108 deletions(-) delete mode 100644 docs/briefs/r3-substrate-descent-execution-proof-canvas.md diff --git a/docs/briefs/r3-substrate-descent-execution-proof-canvas.md b/docs/briefs/r3-substrate-descent-execution-proof-canvas.md deleted file mode 100644 index b97c2bd3d72..00000000000 --- a/docs/briefs/r3-substrate-descent-execution-proof-canvas.md +++ /dev/null @@ -1,108 +0,0 @@ -# Canvas — Substrate `descent_execution_proof` carrier (P1 substrate-fact-introduction) - -**Parent**: gunbc#1939 (Substrate Mgr lane); will be parented under a PM-authored work-item under #1939 post-ratification. -**Authority**: `docs/r3-program-plan.md` §10.3 row Q-EVAL-Descent-Termination-Contract (line 966); Director ratification of split disposition at gunbc#828 #issuecomment-4394696074 (descent_execution_proof STANDS ALONE; folds-into-T-E-P explicitly rejected). -**Closure predicate**: Evaluator E2 descent termination contract consumer (#1971); fail-closed residual enumeration is the load-bearing structural fact. -**Status**: **canvas — Director-tier ratification needed on residual enumeration shape before worker brief authoring**. - -## Scope - -Substrate carrier for executor-side termination-contract verification: - -``` -descent_execution_proof(&Dag, ClusterId, PortId) - -> Result -``` - -Per §10.3 row 966 the residual enumeration was provisionally named `Missing | Unknown | Incomplete | NonStrict`. The shape question is: **what is the minimum-irreducible variant set for `DescentResidual`?** - -## Adjacent substrate (grep-verified at HEAD) - -`src/v3/std/termination.dag:14-17` already defines: - -```dag -type DescentEvidence - = Strict - | NonIncreasing - | DescentUnknown -``` - -with `BoundedLattice` ordering `DescentUnknown < NonIncreasing < Strict` (top = `Strict`, bottom = `DescentUnknown` per fail-closed discipline). `merge_evidence` / `join_evidence` are conservative-meet / optimistic-join. - -So the residual question must reconcile with the existing 3-variant evidence type. **`Unknown` in the residual enumeration ≡ `DescentEvidence::DescentUnknown`**; reusing the existing carrier is the structural-cheap default unless a distinction emerges. - -## Carrier-shape options for the residual enumeration - -### Option α — 4-variant coproduct (as named in §10.3 row 966) - -```dag -type DescentResidual - = Missing // no DescentEvidence carrier present at the call site - | Unknown // DescentEvidence::DescentUnknown surfaced - | Incomplete // per-path evidence exists but some paths uncovered - | NonStrict // evidence is NonIncreasing (not Strict) -``` - -**Pro**: matches §10.3 row 966 verbatim; explicit named cases; readable at the consumer. -**Con**: `Missing` and `Unknown` may collapse — both are "evidence-absent" with different cardinalities (no carrier vs `DescentUnknown` carrier). Per `feedback_coproduct_dissolution`, this is the kind of variant pair that should ratchet downward unless there's a load-bearing distinction. Same for `Incomplete` vs `NonStrict` — both are "evidence-present-but-insufficient", differing on which axis (path-coverage vs strictness). - -### Option β — Dimensional product report - -```dag -type DescentResidualReport { - presence: EvidencePresence // CarrierPresent | CarrierAbsent - completeness: PathCoverage // AllPathsCovered | SomePathsUncovered - strictness: StrictnessVerdict // Strict | NonIncreasing | NotApplicable -} -``` - -Decomposes the 4-coproduct into 3 orthogonal axes; the executor reports per-axis verdict; the "fail" condition is any non-top axis. - -**Pro**: maximum structural decomposition per `feedback_coproduct_dissolution`; eliminates illegal-state question of whether `Incomplete` and `NonStrict` are mutually exclusive (the answer: no — a proof can be both); per-axis independent reasoning. -**Con**: heavier shape; requires defining 3 sub-types (`EvidencePresence`, `PathCoverage`, `StrictnessVerdict`) instead of 1; `StrictnessVerdict::NotApplicable` admits illegal state when carrier is absent (presence=CarrierAbsent + strictness=Strict shouldn't be representable). If the 3 axes don't actually compose orthogonally (i.e., some combinations are nonsensical), product shape is wrong. - -### Option γ — Reuse `DescentEvidence` for "absent/unknown"; 2 additional residuals - -```dag -type DescentResidual - = EvidenceUnknown(DescentEvidence) // wraps DescentUnknown (or NonIncreasing reported as not-strict) - | EvidenceIncomplete // multi-path partial coverage -``` - -3-variant collapse of α: `Missing` and `Unknown` fold into a single `EvidenceUnknown(DescentEvidence)` payload (the `Missing` case is `DescentUnknown` synthesized by the executor when no carrier is present); `NonStrict` folds into `EvidenceUnknown(NonIncreasing)` since the existing lattice already distinguishes `NonIncreasing` from `Strict`; `Incomplete` remains separate because path-coverage IS structurally distinct from per-evidence strictness. - -**Pro**: reuses `DescentEvidence` carrier per `feedback_audit_adjacent_authority_first`; ratchets variant count from 4 → 2 via dimensional folding; `EvidenceUnknown(Strict)` is unrepresentable by construction (Strict isn't a residual). -**Con**: payload-typed variant is heavier than bare-name variant; consumers must pattern-match on the payload to recover the original 4-case story; "Strict" appearing under `EvidenceUnknown` requires an inhabited-only-by-non-Strict refinement type or a runtime check (mild illegal-state risk). - -## Mgr-tier recommendation - -Provisional **γ**: ratchets the variant count via dimensional folding (per Director's coproduct-dissolution audit suggestion) while reusing the existing `DescentEvidence` carrier (services.dag-style "no parallel wrapper" precedent). The `Strict`-shouldn't-appear-here illegal-state risk is mild and addressable via either a refinement type (`DescentEvidence \ Strict`) or a fixture-load fail-closed check. - -If γ's payload-pattern-match cost is unacceptable for consumer ergonomics, **α** with explicit Mgr-acknowledgment that `Missing` ≡ `Unknown` (rather than fold via constructor injection) is the second-best — names the cases verbatim from §10.3 at the cost of one redundant variant. - -**β rejected** unless the 3 axes provably compose orthogonally — risk of admitting illegal states (carrier-absent + strictness=Strict) is real and would require additional refinement-shape work. - -## Director ratification ask - -1. **Pick α / β / γ** (or surface a fourth option). Provisional Mgr recommendation: **γ**. -2. Confirm the existing `DescentEvidence` 3-variant lattice at `termination.dag:14-17` is the authoritative starting point — i.e., the residual carrier composes with it rather than re-inventing it. -3. Confirm the typed signature `descent_execution_proof(&Dag, ClusterId, PortId) -> Result` from §10.3 row 966 is verbatim-binding, OR ratify a refinement (e.g., `&Dag` may need to be `&Dag` + module witness; `ClusterId` + `PortId` are existing Substrate types — verify via grep at worker brief time). - -## On ratification — worker brief scope - -Will author execution brief covering: -- `DescentResidual` carrier in `src/v3/std/termination.dag` (or sibling file if cleaner) per chosen option -- `DescentExecutionProof` carrier shape (witness payload — likely a mini-DAG or per-path evidence map) -- `descent_execution_proof()` substrate function signature in DSL with fail-closed body shape -- Acceptance: §1.8 gates per row 966 closure predicate; bootstrap regen + clippy + workspace tests green -- Cross-Mgr handoff: Evaluator (#1971 / crisp-bat-13) consumes carrier; Q-EVAL-Descent-Termination-Contract row 966 advances to `CONSUMER_LANDED` - -## Worker pin (Mgr disposition) - -**quick-koi-190** — already authorized through quick-crab per §10.3 row 966 ("quick-koi-190 implementation already authorized through quick-crab"); also currently on T-E-P P1 work which is conceptually adjacent (DescentEvidence producer broadening). Final pin at dispatch. - -## Auto-spawn caveat - -Per Director note 2026-05-07: worker auto-spawn from Mgr-context is bug-affected; HOLD dispatch on this canvas's worker brief until auto-spawn fix lands per L-sized-not-low-risk threshold. - -— Authored by warm-wolf-698 (Substrate Mgr) 2026-05-07 post-#2079 merge per Director serial-cadence direction at gunbc#828 #issuecomment-4394696074. Coproduct-dissolution audit per Director's micro-suggestion in same message. From 0cfea88cea6b7041de4ad13f021bd3eef018430a Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 07:43:31 +0000 Subject: [PATCH 21/27] =?UTF-8?q?docs(briefs):=20descent=5Fexecution=5Fpro?= =?UTF-8?q?of=20=E2=80=94=20narrow=20EvidenceUnknown=20payload=20via=20Non?= =?UTF-8?q?StrictEvidence=20subset;=20delete=20superseded=20canvas?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings. 1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict) even though the canvas itself acknowledged Strict-isn't-a-residual as illegal. P2 requires API-level enforcement, not prose convention. Fix: introduce typed subset `NonStrictEvidence = NonIncreasing | DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` — illegal-states-unrepresentable by construction. NonStrictEvidence lands in same file as DescentResidual; composes with existing 3-variant DescentEvidence via inhabitation, not re-definition. 2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with "ratification needed" vs "ratified" status — same P2 single-authority shape as the S5 canvas/worker-brief co-existence at #2079. Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md (worker brief frontmatter already names it as superseded; with canvas gone the live authority is unambiguous). Co-Authored-By: Claude Opus 4.7 (1M context) --- .../r3-substrate-descent-execution-proof-worker.md | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/docs/briefs/r3-substrate-descent-execution-proof-worker.md b/docs/briefs/r3-substrate-descent-execution-proof-worker.md index fbbe9b8b299..023e1991972 100644 --- a/docs/briefs/r3-substrate-descent-execution-proof-worker.md +++ b/docs/briefs/r3-substrate-descent-execution-proof-worker.md @@ -13,11 +13,19 @@ Substrate-fact-introduction (P1 procedure): consumer-side typed substrate functi **Location**: `src/v3/std/termination.dag` (extend the existing file — `DescentEvidence` already lives there; sibling typing keeps the lattice + residual co-located). Verify-via-grep at HEAD that no near-neighbor file has prior claim. ```dag +// Non-Strict subset of DescentEvidence — P2 API-level enforcement: a residual +// can never wrap Strict (Strict means termination IS provable; not a residual). +type NonStrictEvidence + = NonIncreasing + | DescentUnknown + type DescentResidual - = EvidenceUnknown(DescentEvidence) // wraps DescentUnknown for absent-evidence; wraps NonIncreasing for not-strict - | EvidenceIncomplete // proof-construction state: per-path coverage incomplete + = EvidenceUnknown(NonStrictEvidence) // wraps DescentUnknown for absent-evidence; wraps NonIncreasing for not-strict + | EvidenceIncomplete // proof-construction state: per-path coverage incomplete ``` +**Illegal-states-unrepresentable rationale**: the canvas's `EvidenceUnknown(DescentEvidence)` shape would admit `EvidenceUnknown(Strict)` — illegal by construction (Strict means termination is provable, which is not a residual). Per P2 (API-level enforcement over convention), the residual carrier MUST narrow the payload via a typed subset rather than rely on a runtime-only check. `NonStrictEvidence` is the minimum-irreducible 2-variant subset of `DescentEvidence` that's actually a residual. Worker MUST land `NonStrictEvidence` in the same file as `DescentResidual` (`src/v3/std/termination.dag`); compose with existing 3-variant `DescentEvidence` via inhabitation, not by re-defining variants. + **Single substrate function**: ```dag From ce12428637b1f24533e17ba9c838d9433d5bc440 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 07:48:23 +0000 Subject: [PATCH 22/27] =?UTF-8?q?docs(briefs):=20descent=5Fexecution=5Fpro?= =?UTF-8?q?of=20=E2=80=94=20section-anchor=20cite=20for=20=C2=A710.3=20row?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted §10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance (file + section + row all exist) but the line drift IS real. Fix per feedback_section_anchors_over_line_numbers (Director calibration in gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent- Termination-Contract row" — name-anchor instead of line-anchor, drift-immune. 5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP criterion, worker pin justification). Stylistic "row row-text" repetition collapsed to "row text". Co-Authored-By: Claude Opus 4.7 (1M context) --- .../r3-substrate-descent-execution-proof-worker.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/docs/briefs/r3-substrate-descent-execution-proof-worker.md b/docs/briefs/r3-substrate-descent-execution-proof-worker.md index 023e1991972..c28ff29fb6a 100644 --- a/docs/briefs/r3-substrate-descent-execution-proof-worker.md +++ b/docs/briefs/r3-substrate-descent-execution-proof-worker.md @@ -2,7 +2,7 @@ **Sub-issue**: TBD (PM creates under #1939 post-this-brief landing; Evaluator's #1971 `Depends on:` retargets to that issue). **Authority**: Director ratification of **option γ** at gunbc#828 #issuecomment-4395060514 (2026-05-07); supersedes the canvas at `docs/briefs/r3-substrate-descent-execution-proof-canvas.md` (canvas may be deleted after this brief lands). -**Closure predicate**: Evaluator E2 descent termination contract consumer (#1971); §10.3 row 966 row-text refresh to cite γ-disposition (2-variant residual, not 4-variant prose). +**Closure predicate**: Evaluator E2 descent termination contract consumer (#1971); §10.3 Q-EVAL-Descent-Termination-Contract row text refresh to cite γ-disposition (2-variant residual, not 4-variant prose). ## Scope @@ -50,9 +50,9 @@ Per Director: "this is canvas-shape verification, not a re-ratification ask. If 1. **`DescentResidual` carrier landed** in `src/v3/std/termination.dag` (or chosen location post-grep) per ratified γ shape (modulo STOP-resolution on `EvidenceIncomplete` payload). 2. **`DescentExecutionProof` carrier landed** with witness payload shape (per-path evidence map or richer structure surfaced via STOP-and-PING). -3. **`descent_execution_proof()` substrate function landed** with the typed signature from §10.3 row 966 (verbatim per Director confirm). +3. **`descent_execution_proof()` substrate function landed** with the typed signature from §10.3 Q-EVAL-Descent-Termination-Contract row (verbatim per Director confirm). 4. **Evaluator E2 (#1971) consumes the carrier** in same-slice — proves multi-consumer composability is unnecessary for this carrier (Evaluator IS the consumer per closure predicate; carrier-with-single-consumer-as-interface anti-pattern doesn't apply because the carrier is consumer-cementing for executor termination contract). PR description names the Evaluator consumer call site. -5. **§10.3 row 966 row-text update**: ROADMAP cites γ-disposition (2-variant residual) replacing the prose `Missing | Unknown | Incomplete | NonStrict` 4-variant naming. Per Director: "ROADMAP §10.3 row 966 row text should update on Gate A landing to cite this ratification." +5. **§10.3 Q-EVAL-Descent-Termination-Contract row text update**: ROADMAP cites γ-disposition (2-variant residual) replacing the prose `Missing | Unknown | Incomplete | NonStrict` 4-variant naming. Per Director: "ROADMAP §10.3 Q-EVAL-Descent-Termination-Contract row text should update on Gate A landing to cite this ratification." 6. Bootstrap regen: `cargo test -p v3-compiler bootstrap_regen_fresh -- --ignored` clean. 7. Full suite: `cargo test --workspace --exclude v2-compiler-tests` green; `cargo clippy --all-targets -- -D warnings` clean. @@ -60,7 +60,7 @@ Per Director: "this is canvas-shape verification, not a re-ratification ask. If - **STOP** if `EvidenceIncomplete` decomposes into payload-variants per the Director-asked verification above — surface to Mgr (warm-wolf-698 / inbox #2068) before adding a payload; canvas update needed. - **STOP** if `DescentExecutionProof` witness shape requires substantial new substrate (e.g., a fresh per-path-witness type with non-trivial bootstrap-regen impact) — surface scope-creep. -- **STOP** if §10.3 row 966's verbatim signature requires refinement at implementation time (`&Dag` may need module witness; `ClusterId` / `PortId` are existing Substrate types — verify via grep at brief-execution time; surface if drift). +- **STOP** if §10.3 Q-EVAL-Descent-Termination-Contract row's verbatim signature requires refinement at implementation time (`&Dag` may need module witness; `ClusterId` / `PortId` are existing Substrate types — verify via grep at brief-execution time; surface if drift). - **PING** Evaluator Mgr (#2065 / `crisp-bat-13`) at PR-open time so they can retarget #1971 `Depends on:` to the carrier work-item AND begin consumer wiring against the same PR. ## Cross-Mgr coordination @@ -70,7 +70,7 @@ Per Director: "this is canvas-shape verification, not a re-ratification ask. If ## Worker pin (Mgr disposition) -**quick-koi-190** — pre-authorized per §10.3 row 966 ("quick-koi-190 implementation already authorized through quick-crab"); also conceptually adjacent to T-E-P P1 work (DescentEvidence producer broadening) which quick-koi-190 has been on. Final pin at dispatch. +**quick-koi-190** — pre-authorized per §10.3 Q-EVAL-Descent-Termination-Contract row ("quick-koi-190 implementation already authorized through quick-crab"); also conceptually adjacent to T-E-P P1 work (DescentEvidence producer broadening) which quick-koi-190 has been on. Final pin at dispatch. ## Auto-spawn caveat From 93c6f7640d412643fcbceae375a0abab7c999b6b Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 08:56:09 +0000 Subject: [PATCH 23/27] =?UTF-8?q?docs(briefs):=20T-CostLens-Composition=20?= =?UTF-8?q?canvas=20=E2=80=94=20Lens=20composition=20shape?= =?UTF-8?q?=20(#1957)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape authoring. Surfaces 3 composition options for the Lens instance: α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39 no_coercion_cost_dimension by construction) β: single Lens with composed witness in read — strong but requires Lens carrier-shape refactor (target-context threading) γ (recommended): Lens reads structural cost via algebra-fold + target-realization composed via existing Lookup substrate at lookup.dag:48-60 — preserves generic Lens carrier; satisfies all 4 §1.8 gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens), algebra.dag:12+ (SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup + MissingCost lens-boundary). Co-Authored-By: Claude Opus 4.7 (1M context) --- ...substrate-t-costlens-composition-canvas.md | 76 +++++++++++++++++++ 1 file changed, 76 insertions(+) create mode 100644 docs/briefs/r3-substrate-t-costlens-composition-canvas.md diff --git a/docs/briefs/r3-substrate-t-costlens-composition-canvas.md b/docs/briefs/r3-substrate-t-costlens-composition-canvas.md new file mode 100644 index 00000000000..5db2272e436 --- /dev/null +++ b/docs/briefs/r3-substrate-t-costlens-composition-canvas.md @@ -0,0 +1,76 @@ +# Canvas — Substrate T-CostLens-Composition (`Lens` instance shape) + +**Sub-issue**: gunbc#1957 (parented under #1939 Substrate Mgr lane). +**Authority**: `docs/r3-program-plan.md` §10.3 T-CostLens-Composition row at line 399 ("(TBD from Substrate canvas)" — explicitly Substrate Mgr canvas territory); `docs/r3-design-schedule-2026-05-06.md:72` cost-lens-as-discriminator framing. +**Closure predicate**: §1.8 gates #37-40 (structural-fold + thesis-unification + no-separate-cost-dimension + executable predicate) + #70 demonstration. +**Status**: **canvas — Director-tier ratification needed on composition shape before worker brief authoring**. + +## Adjacent substrate (grep-verified at HEAD) + +- `src/v3/std/lens.dag:70-77` defines the generic `Lens` carrier (`read`, `sequential: Monoid`, `branch`, `iterate`, `validate`). Already-landed; NOT subject to redesign. +- `src/v3/std/algebra.dag:12+` defines `SymbolicCost` 7-variant coproduct (`ProductCost`, `SumCost`, etc.) + `Semiring` inhabitance. Algebra-cost side already-substrate. +- `src/v3/std/lookup.dag:48-60` scaffolds `Lookup` + `MissingCost` lens-boundary-fallback shape. +- `src/v3/std/machine_constraints.dag` (per memory + #1933) defines `MachineWidth` substrate; target-realization side has structural facts available. +- `src/v3/std/dimensions.dag:10` notes `data symbolic_cost_dimension: AnalysisDimension` is **deferred** — that's part of the canvas territory. + +## Scope + +T-CostLens-Composition lands a **single `Lens` instance** (or near-equivalent) that composes algebra-cost (already-substrate via `Semiring`) with target-realization-cost (read via `MachineConstraint` / target language spec) end-to-end. Per Director's "cost-lens-as-discriminator" framing: the cost lens orders faithful-representation alternatives by per-primitive realization cost; Grounding selects lowest-cost faithful representation. + +**Key invariant** (gate #39 `no_coercion_cost_dimension`): NO separate cost dimension for coercion vs realization vs algebra — one `SymbolicCost` algebra, all three sources feed into it via `Semiring` operations. + +## Carrier-composition options + +### Option α — Two separate lenses, externally joined + +`Lens` reads algebra-cost only (structural-fold over Behavior + algebra inhabitance); separate `Lens` reads target-realization-cost from LanguageSpec; composition happens at the consumer (Grounding). + +**Pro**: Each lens has a single concern; algebra-cost is target-independent (purer). +**Con**: Violates gate #39 by construction — TWO cost dimensions, joined by convention not by carrier shape. `coercion_cost_equals_complexity_by_construction` (gate #38) would have to be a derived theorem rather than structural-by-construction. Rejected. + +### Option β — Single `Lens` with composed witness in `read` + +`Lens::read(dag, behavior) -> Witness` reads BOTH algebra-cost AND target-realization-cost, composing them via `Semiring` (sum for sequential operations, product for branch/iterate as appropriate). Target-realization-cost obtained via per-primitive lookup keyed on `MachineConstraint` instances at the Behavior's primitives. + +**Pro**: Single cost dimension by construction (gate #39 satisfied structurally); `coercion_cost_equals_complexity_by_construction` is true by construction (gate #38) because coercion is just another operation feeding into the same algebra. End-to-end composition is the carrier's `read` signature. +**Con**: `read` becomes target-aware — needs target-language-spec context threaded through. May force Lens generic's `read: fn(Dag, Behavior) -> Witness` to gain a third parameter (target-context) — substrate-impacting refactor of the generic lens carrier, OR cost lens carries a captured target reference (closure-shape, less structural). + +### Option γ — `Lens` reads structural; target-realization via `Lookup` + +`Lens::read` reads structural-cost via algebra-fold (Behavior + `SymbolicCost` algebra inhabitance); target-realization-cost composed via existing `Lookup` infrastructure at `lookup.dag:48-60`. The lookup is keyed on per-primitive identity (target-spec-derived); when present, lookup-cost composes into the lens output via `Semiring::sum`. + +**Pro**: Reuses existing `Lookup` substrate (per `feedback_audit_adjacent_authority_first` — already authored). Generic `Lens` carrier unchanged; target-realization-cost enters via Lookup's `MissingCost` lens-boundary-fallback shape (already-substrate). Single-cost-dimension preserved (Lookup output IS `SymbolicCost`). `cost_lens_reads_target_realization` (gate #37) is satisfied by Lookup composition; `no_coercion_cost_dimension` (gate #39) is satisfied because Lookup output composes into the same algebra. +**Con**: Lookup-via-Lens-during-read is slightly indirect; consumers must know Lookup is part of the cost computation (vs being lens-internal). Mitigation: lens implementation hides Lookup composition; consumers see only `Lens::read` interface. + +## Mgr-tier recommendation + +Provisional **γ**: composes via existing `Lookup` substrate (already-authored at `lookup.dag:48-60`); preserves generic `Lens` carrier shape unchanged; satisfies all 4 §1.8 gates by construction (#37 via Lookup, #38 via Semiring composition, #39 via single algebra, #40 via the carrier's typed `read` output). Aligns with `feedback_audit_adjacent_authority_first` + `feedback_compositional_not_templating`. + +**β** is second-best if Lookup composition turns out to be insufficient for end-to-end realization-cost reading at canvas-implementation time (e.g., target-realization-cost requires more context than a per-primitive lookup can carry). + +**α rejected** — violates gate #39 by construction. + +## Director ratification ask + +1. **Pick α / β / γ** (or surface fourth option). Provisional Mgr recommendation: **γ** (Lookup composition). +2. Confirm `Lens` generic at `lens.dag:70-77` is authoritative starting point (no carrier-shape refactor in T-CostLens scope). Per option γ this is unchanged; per option β it would refactor. +3. Confirm `data symbolic_cost_dimension: AnalysisDimension` (currently deferred per `dimensions.dag:10`) lands as part of T-CostLens-Composition or stays separately deferred to a Dimensions sub-lane. + +## On ratification — worker brief scope + +Will author execution brief covering: +- `Lens` instance authoring in DSL (likely `src/v3/lenses/cost.dag` per existing convention; verify-via-grep at brief time) +- `read` implementation per chosen option (γ Lookup composition / β composed witness) +- `cost_lens_demonstration` (gate #70): ≥2 algebra-instances composed + ≥1 recursive call + observable cost-bound output — fixture program + executor wiring same-slice +- 4 §1.8 gates (#37-40) advance to executable status +- `data symbolic_cost_dimension` lands or stays deferred per question 3 + +## Worker pin (Mgr disposition) + +Substrate-fact-introduction precedent owners — valiant-ibex-312 (delivered IntPlatform/UIntPlatform, S5 candidate) OR smart-ram-167. Final pin at dispatch. + +## Auto-spawn caveat + +Per Director's standing note + cache-staleness cluster ctrl#217: HOLD dispatch on this canvas's worker brief until auto-spawn fix lands per L-sized substrate-fact-introduction threshold. + +— Authored by warm-wolf-698 (Substrate Mgr) 2026-05-07 post-#2105 merge per Director endorsement of pre-staging T-CostLens-Composition canvas-shape. From 054dcdeb0cc60482d0ee3fc0d3e90c8c8398cc36 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 09:30:11 +0000 Subject: [PATCH 24/27] =?UTF-8?q?docs(briefs):=20T-Workflow-As-Data=20canv?= =?UTF-8?q?as=20=E2=80=94=20audit-receipt-honoring=20scope-narrowing?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983) named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret is wholly net-new substrate. Surfaces 3 options: α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED (admits parallel-representation debt vs audit-receipt #1771 reuse-first directive) β (recommended): minimalist — only WorkflowSecret + Cron refinement net-new; lens consumes extdeps.github.actions directly. Honors feedback_audit_adjacent_authority_first. γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape; natural ratchet from β if evidence accumulates. Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95; brief authoring lands in advance per pre-staging discipline. Co-Authored-By: Claude Opus 4.7 (1M context) --- .../r3-substrate-t-workflow-as-data-canvas.md | 77 +++++++++++++++++++ 1 file changed, 77 insertions(+) create mode 100644 docs/briefs/r3-substrate-t-workflow-as-data-canvas.md diff --git a/docs/briefs/r3-substrate-t-workflow-as-data-canvas.md b/docs/briefs/r3-substrate-t-workflow-as-data-canvas.md new file mode 100644 index 00000000000..69cbf5f039e --- /dev/null +++ b/docs/briefs/r3-substrate-t-workflow-as-data-canvas.md @@ -0,0 +1,77 @@ +# Canvas — Substrate T-Workflow-As-Data carriers (5-row scope-narrowing) + +**Sub-issue**: gunbc#1956 (T-Workflow-As-Data CI-workflow-as-.dag-data demo, parented under #1939); umbrella scope is §10.3 row Q-Workflow-As-Data-Carriers (line 983, OPEN — Substrate Mgr scoping needed). +**Authority**: `docs/r3-program-plan.md:474-480` (5 carrier names) + `docs/r3-design-schedule-2026-05-06.md:84-88` (audit-first directive); `dsl/extdeps/github/actions.dag` (218 lines, already-substrate); audit-and-delta receipt landed 2026-05-06 via #1771 (closed #1873). +**Closure predicate**: §1.8 gates #53 (workflow_substrate_carriers_landed), #54 (timing_lens_carrier_landed), #55 (shared_external_attachment_pattern_documented), #56 (ci_workflow_modeled_as_dag), #62 (substrate_gap_file_ingestion_closed), #63 (substrate_gap_workflow_scheduling_closed). +**Status**: **canvas — Director-tier ratification needed on reuse-vs-new scope before worker brief authoring**. + +## Observation: 4 of 5 named carriers ALREADY exist in `extdeps.github.actions` + +Per §S4 design-schedule directive line 84 (codex BLOCKING 2026-05-06): "S4 worker brief MUST audit `extdeps.github.actions` first and either (a) extend/refine existing carriers via T-Workflow-As-Data lens-consumption-shape additions (preferred per `feedback_audit_adjacent_authority_first` + `feedback_parallel_representation_debt`), or (b) explicitly dissolve `extdeps.github.actions` with a migration path before introducing parallel carriers." + +Grep-verified `dsl/extdeps/github/actions.dag` at HEAD: + +| §10.3 row 983 carrier name | extdeps.github.actions HEAD | Reuse/refine | Net new substrate | +|---|---|---|---| +| `WorkflowTrigger` (Push / PullRequest / Cron / Manual) | `WorkflowTrigger` (Push / PullRequest / Schedule / WorkflowDispatch / WorkflowCall) at `:40` | Refine: `Schedule { cron: String }` → typed `Cron` carrier (per design-schedule:87) | minimal | +| `WorkflowStep` (run command + dependencies + outputs) | `Step` at `:103` | Reuse name `Step`; lens-consumption may add observation anchor | none if pure reuse | +| `WorkflowMatrix` (parameter expansion) | `MatrixStrategy` at `:66+` (inside `Job`) | Reuse + possibly extract as standalone carrier for lens consumption | minimal | +| `WorkflowSecret` (provider-typed, opaque-at-rest, scoped-by-step) | NOT EXTANT in actions.dag at HEAD | **NEW substrate** | full carrier | +| `RunnerResource` (compute class, OS, hardware) | `RunnerSpec` + `RunnerLabel` at `:88+` | Reuse + parameterize as `RunnerResource` for lens-shape consumption | minimal | +| `Workflow` composing carrier | `Workflow` at `:20` (untyped composition) | Refine to parameterized form for lens generic dispatch | minimal | + +**Key finding**: of the 5 named carriers in §10.3 row 983, **only `WorkflowSecret` is wholly new substrate**. The other 4 are reuse-or-refine of existing `extdeps.github.actions` types. The audit-and-delta receipt (#1771, closed via #1873) confirmed this shape; the canvas territory now is **the lens-consumption-shape question**, NOT a 5-carrier-introduction question. + +## Real canvas question (post-audit) + +Given the existing `extdeps.github.actions` substrate is the reuse-base, what's the **minimum additional substrate** needed for T-Workflow-As-Data closure? + +### Option α — Maximalist: introduce all 5 named carriers in `dsl/std/workflow.dag` as parametric refinements + +New file `dsl/std/workflow.dag` declares parameterized versions of all 5 carriers; `extdeps.github.actions` types become specialized instances via composition. New `WorkflowSecret` lands here. + +**Pro**: clean substrate-internal home for T-Workflow-As-Data; lens consumption talks to `dsl/std/workflow.dag` (compiler-internal vocabulary), not `dsl/extdeps/github/` (external-tool vocabulary). +**Con**: introduces parallel-representation debt with `extdeps.github.actions` (per `feedback_parallel_representation_debt`). The audit-receipt's reuse-first directive argues against this. 5 new types when only 1 is wholly novel. + +### Option β — Minimalist (audit-receipt-honoring): land only `WorkflowSecret` + `Cron` refinement; lens consumes existing `extdeps.github.actions` types directly + +Single new file `dsl/std/workflow_secret.dag` (or fold into `extdeps.github.actions` if scope-cohering) carrying `WorkflowSecret` + the typed `Cron` refinement. Lens-consumption shapes (e.g., `WorkflowObservationAnchor`) land in `dsl/std/workflow.dag` separately if/when needed by the lens; T-Workflow-As-Data's CI-workflow-as-.dag-data demo (#1956) consumes the refined `extdeps.github.actions` directly. + +**Pro**: minimal substrate addition; honors audit-receipt's reuse-first directive (`feedback_audit_adjacent_authority_first`); single point of new-substrate, single point of refinement. No parallel-representation debt. +**Con**: lens consumption talks to `extdeps.github.actions` (external-tool vocabulary) — may look conceptually inconsistent with other lens consumers reading `dsl/std/*` types. Mitigation: documented as deliberate audit-receipt outcome. + +### Option γ — Lens-consumption-shape carrier separately + minimal new substrate + +Like β but with `WorkflowObservationAnchor` (per Substrate Mgr design stance at gunbc#1130 comment-4374109666) explicitly authored alongside `WorkflowSecret`. The lens-consumption layer is its own typed carrier; doesn't conflate with `extdeps.github.actions` reuse. + +**Pro**: separates "external-tool vocabulary" (extdeps.github.actions, reuse) from "lens-consumption substrate" (new `WorkflowObservationAnchor`); each layer has single concern. Lens consumers read `WorkflowObservationAnchor`, which references `extdeps.github.actions::Workflow` structurally. +**Con**: 2 new substrate carriers vs β's 1; mild scope expansion. Justifiable IF lens-consumption-shape genuinely needs typed handle distinct from `extdeps.github.actions::Workflow`. + +## Mgr-tier recommendation + +Provisional **β** (minimalist, audit-receipt-honoring): only `WorkflowSecret` + `Cron` refinement land as net-new substrate. Lens consumes `extdeps.github.actions` directly until evidence shows a typed lens-handle is needed. **γ** is the natural ratchet from β if lens-consumption-shape evidence accumulates (per `feedback_construction_over_ratchets` — model first, dissolve later if substrate evidence forces). + +**α rejected** — admits parallel-representation debt against `extdeps.github.actions` audit-receipt findings. + +## Director ratification ask + +1. **Pick α / β / γ** (or surface fourth). Mgr recommendation: **β**. +2. Confirm `extdeps.github.actions` audit-receipt at #1771 is the binding precedent for reuse-first posture (i.e., the audit confirmed reuse is the right shape, not deprecation). +3. Confirm `WorkflowSecret` location: `dsl/std/workflow_secret.dag` (new file) vs fold into existing `extdeps.github.actions` (extension). Provisional Mgr preference: **new file** (compiler-internal substrate, distinct from external-tool vocabulary; honors layer model). +4. Confirm whether §1.8 gate #54 (`timing_lens_carrier_landed`) and gate #55 (`shared_external_attachment_pattern_documented`) are in T-Workflow-As-Data scope or fold to T-LBP / separate sub-lane. + +## On ratification — worker brief scope + +Will author execution brief covering: +- `WorkflowSecret` carrier (`dsl/std/workflow_secret.dag` per option β/γ) +- `Cron` typed refinement (location TBD per question 3) +- (γ only) `WorkflowObservationAnchor` lens-consumption-shape carrier +- Worker pin: substrate-fact-introduction precedent owners (valiant-ibex-312 / smart-ram-167) +- Acceptance: §1.8 gates #53-#56 + #62-#63 advance per closure-predicate scope +- T-Workflow-As-Data #1956 demo consumer wiring (CI-workflow-as-.dag-data) in same-slice or cross-Mgr handoff per Director ratification + +## Sequencing caveat + +Per §S4 design-schedule line 95: "post-T-Lens-Behavioral-Parity COMPLETE (per `r3-structure.md` §"Dependency on R2"; lens consumption needs lenses COMPLETE)". This canvas is dispatch-ready post-T-LBP COMPLETE; brief authoring can land in advance per pre-staging discipline but worker dispatch waits. + +— Authored by warm-wolf-698 (Substrate Mgr) 2026-05-07 post-#2105 merge per Director endorsement of pre-staging next-up substrate canvases. Honors audit-and-delta receipt #1771 (closed #1873) reuse-first directive. From 102071e509d25e36554ba5255a795f0596d78359 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 10:04:25 +0000 Subject: [PATCH 25/27] =?UTF-8?q?docs(briefs):=20T-CostLens-Composition=20?= =?UTF-8?q?worker=20brief=20=E2=80=94=20=CE=B3=20ratified;=20delete=20canv?= =?UTF-8?q?as?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Director ratification at gunbc#828 #issuecomment-4395691775: - γ option ratified (Lens + Lookup composition) - Lens generic at lens.dag:70-77 confirmed authoritative (no refactor in scope) - symbolic_cost_dimension: AnalysisDimension defers to separate Dimensions sub-lane Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status: STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is behavioral-completion + target-realization-wiring, NOT P1 carrier introduction. Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via Lookup composition. 8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens status header refresh + §10.3 row text refresh. Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens generic refactor (STOP-and-PING if implementation reveals need). Canvas deleted per single-authority discipline (same precedent as S5 + descent_execution_proof canvas deletions). Co-Authored-By: Claude Opus 4.7 (1M context) --- ...substrate-t-costlens-composition-canvas.md | 76 ------------------- ...substrate-t-costlens-composition-worker.md | 66 ++++++++++++++++ 2 files changed, 66 insertions(+), 76 deletions(-) delete mode 100644 docs/briefs/r3-substrate-t-costlens-composition-canvas.md create mode 100644 docs/briefs/r3-substrate-t-costlens-composition-worker.md diff --git a/docs/briefs/r3-substrate-t-costlens-composition-canvas.md b/docs/briefs/r3-substrate-t-costlens-composition-canvas.md deleted file mode 100644 index 5db2272e436..00000000000 --- a/docs/briefs/r3-substrate-t-costlens-composition-canvas.md +++ /dev/null @@ -1,76 +0,0 @@ -# Canvas — Substrate T-CostLens-Composition (`Lens` instance shape) - -**Sub-issue**: gunbc#1957 (parented under #1939 Substrate Mgr lane). -**Authority**: `docs/r3-program-plan.md` §10.3 T-CostLens-Composition row at line 399 ("(TBD from Substrate canvas)" — explicitly Substrate Mgr canvas territory); `docs/r3-design-schedule-2026-05-06.md:72` cost-lens-as-discriminator framing. -**Closure predicate**: §1.8 gates #37-40 (structural-fold + thesis-unification + no-separate-cost-dimension + executable predicate) + #70 demonstration. -**Status**: **canvas — Director-tier ratification needed on composition shape before worker brief authoring**. - -## Adjacent substrate (grep-verified at HEAD) - -- `src/v3/std/lens.dag:70-77` defines the generic `Lens` carrier (`read`, `sequential: Monoid`, `branch`, `iterate`, `validate`). Already-landed; NOT subject to redesign. -- `src/v3/std/algebra.dag:12+` defines `SymbolicCost` 7-variant coproduct (`ProductCost`, `SumCost`, etc.) + `Semiring` inhabitance. Algebra-cost side already-substrate. -- `src/v3/std/lookup.dag:48-60` scaffolds `Lookup` + `MissingCost` lens-boundary-fallback shape. -- `src/v3/std/machine_constraints.dag` (per memory + #1933) defines `MachineWidth` substrate; target-realization side has structural facts available. -- `src/v3/std/dimensions.dag:10` notes `data symbolic_cost_dimension: AnalysisDimension` is **deferred** — that's part of the canvas territory. - -## Scope - -T-CostLens-Composition lands a **single `Lens` instance** (or near-equivalent) that composes algebra-cost (already-substrate via `Semiring`) with target-realization-cost (read via `MachineConstraint` / target language spec) end-to-end. Per Director's "cost-lens-as-discriminator" framing: the cost lens orders faithful-representation alternatives by per-primitive realization cost; Grounding selects lowest-cost faithful representation. - -**Key invariant** (gate #39 `no_coercion_cost_dimension`): NO separate cost dimension for coercion vs realization vs algebra — one `SymbolicCost` algebra, all three sources feed into it via `Semiring` operations. - -## Carrier-composition options - -### Option α — Two separate lenses, externally joined - -`Lens` reads algebra-cost only (structural-fold over Behavior + algebra inhabitance); separate `Lens` reads target-realization-cost from LanguageSpec; composition happens at the consumer (Grounding). - -**Pro**: Each lens has a single concern; algebra-cost is target-independent (purer). -**Con**: Violates gate #39 by construction — TWO cost dimensions, joined by convention not by carrier shape. `coercion_cost_equals_complexity_by_construction` (gate #38) would have to be a derived theorem rather than structural-by-construction. Rejected. - -### Option β — Single `Lens` with composed witness in `read` - -`Lens::read(dag, behavior) -> Witness` reads BOTH algebra-cost AND target-realization-cost, composing them via `Semiring` (sum for sequential operations, product for branch/iterate as appropriate). Target-realization-cost obtained via per-primitive lookup keyed on `MachineConstraint` instances at the Behavior's primitives. - -**Pro**: Single cost dimension by construction (gate #39 satisfied structurally); `coercion_cost_equals_complexity_by_construction` is true by construction (gate #38) because coercion is just another operation feeding into the same algebra. End-to-end composition is the carrier's `read` signature. -**Con**: `read` becomes target-aware — needs target-language-spec context threaded through. May force Lens generic's `read: fn(Dag, Behavior) -> Witness` to gain a third parameter (target-context) — substrate-impacting refactor of the generic lens carrier, OR cost lens carries a captured target reference (closure-shape, less structural). - -### Option γ — `Lens` reads structural; target-realization via `Lookup` - -`Lens::read` reads structural-cost via algebra-fold (Behavior + `SymbolicCost` algebra inhabitance); target-realization-cost composed via existing `Lookup` infrastructure at `lookup.dag:48-60`. The lookup is keyed on per-primitive identity (target-spec-derived); when present, lookup-cost composes into the lens output via `Semiring::sum`. - -**Pro**: Reuses existing `Lookup` substrate (per `feedback_audit_adjacent_authority_first` — already authored). Generic `Lens` carrier unchanged; target-realization-cost enters via Lookup's `MissingCost` lens-boundary-fallback shape (already-substrate). Single-cost-dimension preserved (Lookup output IS `SymbolicCost`). `cost_lens_reads_target_realization` (gate #37) is satisfied by Lookup composition; `no_coercion_cost_dimension` (gate #39) is satisfied because Lookup output composes into the same algebra. -**Con**: Lookup-via-Lens-during-read is slightly indirect; consumers must know Lookup is part of the cost computation (vs being lens-internal). Mitigation: lens implementation hides Lookup composition; consumers see only `Lens::read` interface. - -## Mgr-tier recommendation - -Provisional **γ**: composes via existing `Lookup` substrate (already-authored at `lookup.dag:48-60`); preserves generic `Lens` carrier shape unchanged; satisfies all 4 §1.8 gates by construction (#37 via Lookup, #38 via Semiring composition, #39 via single algebra, #40 via the carrier's typed `read` output). Aligns with `feedback_audit_adjacent_authority_first` + `feedback_compositional_not_templating`. - -**β** is second-best if Lookup composition turns out to be insufficient for end-to-end realization-cost reading at canvas-implementation time (e.g., target-realization-cost requires more context than a per-primitive lookup can carry). - -**α rejected** — violates gate #39 by construction. - -## Director ratification ask - -1. **Pick α / β / γ** (or surface fourth option). Provisional Mgr recommendation: **γ** (Lookup composition). -2. Confirm `Lens` generic at `lens.dag:70-77` is authoritative starting point (no carrier-shape refactor in T-CostLens scope). Per option γ this is unchanged; per option β it would refactor. -3. Confirm `data symbolic_cost_dimension: AnalysisDimension` (currently deferred per `dimensions.dag:10`) lands as part of T-CostLens-Composition or stays separately deferred to a Dimensions sub-lane. - -## On ratification — worker brief scope - -Will author execution brief covering: -- `Lens` instance authoring in DSL (likely `src/v3/lenses/cost.dag` per existing convention; verify-via-grep at brief time) -- `read` implementation per chosen option (γ Lookup composition / β composed witness) -- `cost_lens_demonstration` (gate #70): ≥2 algebra-instances composed + ≥1 recursive call + observable cost-bound output — fixture program + executor wiring same-slice -- 4 §1.8 gates (#37-40) advance to executable status -- `data symbolic_cost_dimension` lands or stays deferred per question 3 - -## Worker pin (Mgr disposition) - -Substrate-fact-introduction precedent owners — valiant-ibex-312 (delivered IntPlatform/UIntPlatform, S5 candidate) OR smart-ram-167. Final pin at dispatch. - -## Auto-spawn caveat - -Per Director's standing note + cache-staleness cluster ctrl#217: HOLD dispatch on this canvas's worker brief until auto-spawn fix lands per L-sized substrate-fact-introduction threshold. - -— Authored by warm-wolf-698 (Substrate Mgr) 2026-05-07 post-#2105 merge per Director endorsement of pre-staging T-CostLens-Composition canvas-shape. diff --git a/docs/briefs/r3-substrate-t-costlens-composition-worker.md b/docs/briefs/r3-substrate-t-costlens-composition-worker.md new file mode 100644 index 00000000000..bee4a910dbe --- /dev/null +++ b/docs/briefs/r3-substrate-t-costlens-composition-worker.md @@ -0,0 +1,66 @@ +# Worker brief — Substrate T-CostLens-Composition (γ ratified) + +**Sub-issue**: gunbc#1957 (parented under #1939 Substrate Mgr lane). +**Authority**: Director ratification of **option γ** at gunbc#828 #issuecomment-4395691775 (2026-05-07); supersedes the canvas at `docs/briefs/r3-substrate-t-costlens-composition-canvas.md` (canvas may be deleted after this brief lands per single-authority discipline). +**Closure predicate**: §1.8 gates #37 `cost_lens_reads_target_realization`, #38 `coercion_cost_equals_complexity_by_construction`, #39 `no_coercion_cost_dimension`, #40 `symbolic_cost_expr_equals_executable`, plus #70 `cost_lens_demonstration`. + +## Important framing — this is NOT a substrate-fact-introduction + +`src/v3/lenses/cost.dag` ALREADY EXISTS at HEAD as a `STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY` lens (per the file's status header). T-CostLens-Composition is **behavioral-completion + target-realization-wiring**, NOT P1 carrier introduction. Substrate primitives are all already-substrate: + +- `Lens` generic at `src/v3/std/lens.dag:70-77` — **untouched** per Director ratification (any refactor is separate scope, STOP-and-PING) +- `SymbolicCost` 7-variant + `Semiring` at `src/v3/std/algebra.dag:12+` +- `Lookup` + `MissingCost` lens-boundary-fallback at `src/v3/std/lookup.dag:48-60` +- `lenses/cost.dag` lens-instance scaffolding (existing behavioral PROXY) + +Worker should **read the existing `lenses/cost.dag`** before doing anything else; the work is to advance it from PROXY → BEHAVIORALLY COMPLETE via target-realization composition, NOT to manufacture parallel substrate. + +## Scope (binding per Director γ ratification) + +Wire target-realization-cost into the existing `lenses/cost.dag` `Lens` instance via `Lookup` composition, satisfying all 4 §1.8 gates by construction: + +- **#37 `cost_lens_reads_target_realization`** — lens output reads target-realization cost from `Lookup` keyed on per-primitive identity (target-spec-derived). `MissingCost` lens-boundary-fallback already substrate at `lookup.dag:48-60`. +- **#38 `coercion_cost_equals_complexity_by_construction`** — coercion-cost composes into the same `SymbolicCost` algebra as algebra-cost via `Semiring::sum` / `::product`; the equation is structural, not derived. +- **#39 `no_coercion_cost_dimension`** — single `SymbolicCost` algebra; no parallel cost dimension. The existing lens is already structurally aligned (uses `std.algebra::sequential`/`iterate`/`max_path`); worker confirms no parallel dimension introduced. +- **#40 `symbolic_cost_expr_equals_executable`** — runtime-executable `SymbolicCostExprEquals` predicate consuming the lens output. Test_runner / cementing-test harness wiring per existing infrastructure. + +Plus **#70 `cost_lens_demonstration`** — fixture program with ≥2 algebra-instances composed + ≥1 recursive call + observable cost-bound output. Same-slice acceptance. + +## Out-of-scope (deferred per Director ratification) + +- `data symbolic_cost_dimension: AnalysisDimension` — Director ratified DEFER to separate Dimensions sub-lane (per §10.3 Q-CostLens-Dimensions framing if/when authored). T-CostLens proceeds without it; consumes the dimension as structural fact only when it lands. +- `Lens` generic carrier-shape refactor — STOP-and-PING the Mgr if implementation reveals a need; that's separate Director-tier scope question, NOT T-CostLens absorption. + +## Acceptance gates (same-slice, all must pass) + +1. `lenses/cost.dag` advanced from `STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY` → `BEHAVIORALLY COMPLETE` per `docs/v3-lens-capability-register.md` audit; status header updated in the file itself. +2. **#37 satisfied**: lens output documented to read target-realization cost via `Lookup`. Code-level cite in PR description. +3. **#38 + #39 satisfied by construction**: lens output is `SymbolicCost`-typed; no parallel cost dimension visible in the diff. Verified via grep at acceptance time. +4. **#40 satisfied**: `SymbolicCostExprEquals` predicate executable in test_runner; runtime predicate evaluates against representative input (NOT NotYetImplemented shell). +5. **#70 satisfied**: `cost_lens_demonstration` fixture program lands at `src/v3/compiler/tests/integration/` (or appropriate fixture location); ≥2 algebra-instances + ≥1 recursive call + observable cost-bound output verified by demonstration test. +6. Bootstrap regen: `cargo test -p v3-compiler bootstrap_regen_fresh -- --ignored` clean. +7. Full suite: `cargo test --workspace --exclude v2-compiler-tests` green; `cargo clippy --all-targets -- -D warnings` clean. +8. **§10.3 row text refresh**: `docs/r3-program-plan.md` §10.3 T-CostLens-Composition row (currently "(TBD from Substrate canvas)") updated to cite γ-disposition + this PR's # as the receipt. + +## STOP / PING criteria + +- **STOP** if implementation reveals `Lens` generic at `lens.dag:70-77` needs carrier-shape refactor (e.g., `read: fn(Dag, Behavior) -> Witness` needs target-context threading) — that's separate Director-tier scope per Director's confirmed ask #2; do NOT absorb into T-CostLens. +- **STOP** if `Lookup` composition is structurally insufficient for end-to-end realization-cost reading (e.g., target-realization-cost requires more context than per-primitive lookup can carry) — surface to Mgr; canvas option β (composed-witness) may need re-ratification. +- **STOP** if `cost_lens_demonstration` fixture authoring requires `data symbolic_cost_dimension` to be present — that contradicts Director's defer disposition; surface to Mgr to resolve cross-lane dependency. +- **PING** Verification Mgr (#2075 / `wise-bear-525`) at PR-open time so they can advance Pattern-A executable gate #40 `symbolic_cost_expr_equals_executable` per §1.6 NYI → executable transition discipline. + +## Cross-Mgr coordination + +- **Verification Mgr (#2075)**: PING at PR-open per gate #40 transition; ratchet authoring is Verification's standing concern. +- **Grounding Mgr**: target-realization-cost reading depends on target language spec (per `r3-design-schedule:72` cost-lens-as-discriminator). If target-spec data isn't yet populated for the demonstration fixture's targets, surface to Grounding Mgr (#1944 / current active session) for cross-lane data population. +- **R4-carve note**: T-LBP option (b) RATIFIED 2026-05-06 means T-LBP R3 scope = complexity + cost lenses only. T-CostLens-Composition closing simultaneously with `cost_lens_behaviorally_complete` (gate #80) is the critical-path-fastest sequencing per Q-LBP option (b). + +## Worker pin (Mgr disposition) + +Substrate-fact-introduction precedent owners — **valiant-ibex-312** (delivered IntPlatform/UIntPlatform via PR #1933, S5 candidate) OR **smart-ram-167**. Lens-behavioral work also has precedent owners; final pin at dispatch. + +## Auto-spawn caveat + +Per Director's standing note + cache-staleness cluster ctrl#217: HOLD dispatch on this brief until auto-spawn fix lands per L-sized substrate-behavioral-completion threshold, OR Mgr-direct authoring if scope-cohering small-enough (this is L-sized; Mgr-direct is unlikely fit unless Director ratifies surgical-recreate path for cascade unblock). + +— Authored by warm-wolf-698 (Substrate Mgr) 2026-05-07 post-#2112 merge per Director γ-ratification at gunbc#828 #issuecomment-4395691775. From 34faf0c16a05c42d180d9cdd19b6f1f93e5a0ee5 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 10:04:41 +0000 Subject: [PATCH 26/27] Delete superseded T-CostLens canvas (worker brief is single live authority) --- ...substrate-t-costlens-composition-canvas.md | 76 ------------------- 1 file changed, 76 deletions(-) delete mode 100644 docs/briefs/r3-substrate-t-costlens-composition-canvas.md diff --git a/docs/briefs/r3-substrate-t-costlens-composition-canvas.md b/docs/briefs/r3-substrate-t-costlens-composition-canvas.md deleted file mode 100644 index 5db2272e436..00000000000 --- a/docs/briefs/r3-substrate-t-costlens-composition-canvas.md +++ /dev/null @@ -1,76 +0,0 @@ -# Canvas — Substrate T-CostLens-Composition (`Lens` instance shape) - -**Sub-issue**: gunbc#1957 (parented under #1939 Substrate Mgr lane). -**Authority**: `docs/r3-program-plan.md` §10.3 T-CostLens-Composition row at line 399 ("(TBD from Substrate canvas)" — explicitly Substrate Mgr canvas territory); `docs/r3-design-schedule-2026-05-06.md:72` cost-lens-as-discriminator framing. -**Closure predicate**: §1.8 gates #37-40 (structural-fold + thesis-unification + no-separate-cost-dimension + executable predicate) + #70 demonstration. -**Status**: **canvas — Director-tier ratification needed on composition shape before worker brief authoring**. - -## Adjacent substrate (grep-verified at HEAD) - -- `src/v3/std/lens.dag:70-77` defines the generic `Lens` carrier (`read`, `sequential: Monoid`, `branch`, `iterate`, `validate`). Already-landed; NOT subject to redesign. -- `src/v3/std/algebra.dag:12+` defines `SymbolicCost` 7-variant coproduct (`ProductCost`, `SumCost`, etc.) + `Semiring` inhabitance. Algebra-cost side already-substrate. -- `src/v3/std/lookup.dag:48-60` scaffolds `Lookup` + `MissingCost` lens-boundary-fallback shape. -- `src/v3/std/machine_constraints.dag` (per memory + #1933) defines `MachineWidth` substrate; target-realization side has structural facts available. -- `src/v3/std/dimensions.dag:10` notes `data symbolic_cost_dimension: AnalysisDimension` is **deferred** — that's part of the canvas territory. - -## Scope - -T-CostLens-Composition lands a **single `Lens` instance** (or near-equivalent) that composes algebra-cost (already-substrate via `Semiring`) with target-realization-cost (read via `MachineConstraint` / target language spec) end-to-end. Per Director's "cost-lens-as-discriminator" framing: the cost lens orders faithful-representation alternatives by per-primitive realization cost; Grounding selects lowest-cost faithful representation. - -**Key invariant** (gate #39 `no_coercion_cost_dimension`): NO separate cost dimension for coercion vs realization vs algebra — one `SymbolicCost` algebra, all three sources feed into it via `Semiring` operations. - -## Carrier-composition options - -### Option α — Two separate lenses, externally joined - -`Lens` reads algebra-cost only (structural-fold over Behavior + algebra inhabitance); separate `Lens` reads target-realization-cost from LanguageSpec; composition happens at the consumer (Grounding). - -**Pro**: Each lens has a single concern; algebra-cost is target-independent (purer). -**Con**: Violates gate #39 by construction — TWO cost dimensions, joined by convention not by carrier shape. `coercion_cost_equals_complexity_by_construction` (gate #38) would have to be a derived theorem rather than structural-by-construction. Rejected. - -### Option β — Single `Lens` with composed witness in `read` - -`Lens::read(dag, behavior) -> Witness` reads BOTH algebra-cost AND target-realization-cost, composing them via `Semiring` (sum for sequential operations, product for branch/iterate as appropriate). Target-realization-cost obtained via per-primitive lookup keyed on `MachineConstraint` instances at the Behavior's primitives. - -**Pro**: Single cost dimension by construction (gate #39 satisfied structurally); `coercion_cost_equals_complexity_by_construction` is true by construction (gate #38) because coercion is just another operation feeding into the same algebra. End-to-end composition is the carrier's `read` signature. -**Con**: `read` becomes target-aware — needs target-language-spec context threaded through. May force Lens generic's `read: fn(Dag, Behavior) -> Witness` to gain a third parameter (target-context) — substrate-impacting refactor of the generic lens carrier, OR cost lens carries a captured target reference (closure-shape, less structural). - -### Option γ — `Lens` reads structural; target-realization via `Lookup` - -`Lens::read` reads structural-cost via algebra-fold (Behavior + `SymbolicCost` algebra inhabitance); target-realization-cost composed via existing `Lookup` infrastructure at `lookup.dag:48-60`. The lookup is keyed on per-primitive identity (target-spec-derived); when present, lookup-cost composes into the lens output via `Semiring::sum`. - -**Pro**: Reuses existing `Lookup` substrate (per `feedback_audit_adjacent_authority_first` — already authored). Generic `Lens` carrier unchanged; target-realization-cost enters via Lookup's `MissingCost` lens-boundary-fallback shape (already-substrate). Single-cost-dimension preserved (Lookup output IS `SymbolicCost`). `cost_lens_reads_target_realization` (gate #37) is satisfied by Lookup composition; `no_coercion_cost_dimension` (gate #39) is satisfied because Lookup output composes into the same algebra. -**Con**: Lookup-via-Lens-during-read is slightly indirect; consumers must know Lookup is part of the cost computation (vs being lens-internal). Mitigation: lens implementation hides Lookup composition; consumers see only `Lens::read` interface. - -## Mgr-tier recommendation - -Provisional **γ**: composes via existing `Lookup` substrate (already-authored at `lookup.dag:48-60`); preserves generic `Lens` carrier shape unchanged; satisfies all 4 §1.8 gates by construction (#37 via Lookup, #38 via Semiring composition, #39 via single algebra, #40 via the carrier's typed `read` output). Aligns with `feedback_audit_adjacent_authority_first` + `feedback_compositional_not_templating`. - -**β** is second-best if Lookup composition turns out to be insufficient for end-to-end realization-cost reading at canvas-implementation time (e.g., target-realization-cost requires more context than a per-primitive lookup can carry). - -**α rejected** — violates gate #39 by construction. - -## Director ratification ask - -1. **Pick α / β / γ** (or surface fourth option). Provisional Mgr recommendation: **γ** (Lookup composition). -2. Confirm `Lens` generic at `lens.dag:70-77` is authoritative starting point (no carrier-shape refactor in T-CostLens scope). Per option γ this is unchanged; per option β it would refactor. -3. Confirm `data symbolic_cost_dimension: AnalysisDimension` (currently deferred per `dimensions.dag:10`) lands as part of T-CostLens-Composition or stays separately deferred to a Dimensions sub-lane. - -## On ratification — worker brief scope - -Will author execution brief covering: -- `Lens` instance authoring in DSL (likely `src/v3/lenses/cost.dag` per existing convention; verify-via-grep at brief time) -- `read` implementation per chosen option (γ Lookup composition / β composed witness) -- `cost_lens_demonstration` (gate #70): ≥2 algebra-instances composed + ≥1 recursive call + observable cost-bound output — fixture program + executor wiring same-slice -- 4 §1.8 gates (#37-40) advance to executable status -- `data symbolic_cost_dimension` lands or stays deferred per question 3 - -## Worker pin (Mgr disposition) - -Substrate-fact-introduction precedent owners — valiant-ibex-312 (delivered IntPlatform/UIntPlatform, S5 candidate) OR smart-ram-167. Final pin at dispatch. - -## Auto-spawn caveat - -Per Director's standing note + cache-staleness cluster ctrl#217: HOLD dispatch on this canvas's worker brief until auto-spawn fix lands per L-sized substrate-fact-introduction threshold. - -— Authored by warm-wolf-698 (Substrate Mgr) 2026-05-07 post-#2105 merge per Director endorsement of pre-staging T-CostLens-Composition canvas-shape. From b7d808e48ee5df7cf4b1e2c8f510a08fd553c42c Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 7 May 2026 11:17:30 +0000 Subject: [PATCH 27/27] =?UTF-8?q?docs(briefs):=20T-WAD=20Slice=201=20worke?= =?UTF-8?q?r=20brief=20=E2=80=94=20=CE=B2=20ratified;=20delete=20canvas?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed: 1. β ratified (minimalist reuse-first) 2. #1771 audit-receipt binding precedent confirmed 3. WorkflowSecret folds into dsl/extdeps/github/actions.dag (provider- specific scope; NOT new dsl/std/ file unless cross-provider evidence) 4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern; slice 3 = ci_workflow_modeled_as_dag) Slice 1 net-new substrate (only): - WorkflowSecret + SecretScope carriers - CronExpression + CronField (typed refinement of existing WorkflowTrigger::Schedule { cron: String } at actions.dag:43) Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions per audit-receipt #1771 directive. 6 same-slice acceptance gates incl no-parallel-representation grep + gate #53/#62/#63 advancement + bootstrap regen + clippy. Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent provider work for WorkflowSecret-shape evidence; surfaces if found before finalizing fold-into-extdeps. Canvas deleted per single-authority discipline (S5 + descent_execution_proof + T-CostLens precedent). Co-Authored-By: Claude Opus 4.7 (1M context) --- .../r3-substrate-t-workflow-as-data-canvas.md | 77 -------------- ...trate-t-workflow-as-data-slice-1-worker.md | 100 ++++++++++++++++++ 2 files changed, 100 insertions(+), 77 deletions(-) delete mode 100644 docs/briefs/r3-substrate-t-workflow-as-data-canvas.md create mode 100644 docs/briefs/r3-substrate-t-workflow-as-data-slice-1-worker.md diff --git a/docs/briefs/r3-substrate-t-workflow-as-data-canvas.md b/docs/briefs/r3-substrate-t-workflow-as-data-canvas.md deleted file mode 100644 index 69cbf5f039e..00000000000 --- a/docs/briefs/r3-substrate-t-workflow-as-data-canvas.md +++ /dev/null @@ -1,77 +0,0 @@ -# Canvas — Substrate T-Workflow-As-Data carriers (5-row scope-narrowing) - -**Sub-issue**: gunbc#1956 (T-Workflow-As-Data CI-workflow-as-.dag-data demo, parented under #1939); umbrella scope is §10.3 row Q-Workflow-As-Data-Carriers (line 983, OPEN — Substrate Mgr scoping needed). -**Authority**: `docs/r3-program-plan.md:474-480` (5 carrier names) + `docs/r3-design-schedule-2026-05-06.md:84-88` (audit-first directive); `dsl/extdeps/github/actions.dag` (218 lines, already-substrate); audit-and-delta receipt landed 2026-05-06 via #1771 (closed #1873). -**Closure predicate**: §1.8 gates #53 (workflow_substrate_carriers_landed), #54 (timing_lens_carrier_landed), #55 (shared_external_attachment_pattern_documented), #56 (ci_workflow_modeled_as_dag), #62 (substrate_gap_file_ingestion_closed), #63 (substrate_gap_workflow_scheduling_closed). -**Status**: **canvas — Director-tier ratification needed on reuse-vs-new scope before worker brief authoring**. - -## Observation: 4 of 5 named carriers ALREADY exist in `extdeps.github.actions` - -Per §S4 design-schedule directive line 84 (codex BLOCKING 2026-05-06): "S4 worker brief MUST audit `extdeps.github.actions` first and either (a) extend/refine existing carriers via T-Workflow-As-Data lens-consumption-shape additions (preferred per `feedback_audit_adjacent_authority_first` + `feedback_parallel_representation_debt`), or (b) explicitly dissolve `extdeps.github.actions` with a migration path before introducing parallel carriers." - -Grep-verified `dsl/extdeps/github/actions.dag` at HEAD: - -| §10.3 row 983 carrier name | extdeps.github.actions HEAD | Reuse/refine | Net new substrate | -|---|---|---|---| -| `WorkflowTrigger` (Push / PullRequest / Cron / Manual) | `WorkflowTrigger` (Push / PullRequest / Schedule / WorkflowDispatch / WorkflowCall) at `:40` | Refine: `Schedule { cron: String }` → typed `Cron` carrier (per design-schedule:87) | minimal | -| `WorkflowStep` (run command + dependencies + outputs) | `Step` at `:103` | Reuse name `Step`; lens-consumption may add observation anchor | none if pure reuse | -| `WorkflowMatrix` (parameter expansion) | `MatrixStrategy` at `:66+` (inside `Job`) | Reuse + possibly extract as standalone carrier for lens consumption | minimal | -| `WorkflowSecret` (provider-typed, opaque-at-rest, scoped-by-step) | NOT EXTANT in actions.dag at HEAD | **NEW substrate** | full carrier | -| `RunnerResource` (compute class, OS, hardware) | `RunnerSpec` + `RunnerLabel` at `:88+` | Reuse + parameterize as `RunnerResource` for lens-shape consumption | minimal | -| `Workflow` composing carrier | `Workflow` at `:20` (untyped composition) | Refine to parameterized form for lens generic dispatch | minimal | - -**Key finding**: of the 5 named carriers in §10.3 row 983, **only `WorkflowSecret` is wholly new substrate**. The other 4 are reuse-or-refine of existing `extdeps.github.actions` types. The audit-and-delta receipt (#1771, closed via #1873) confirmed this shape; the canvas territory now is **the lens-consumption-shape question**, NOT a 5-carrier-introduction question. - -## Real canvas question (post-audit) - -Given the existing `extdeps.github.actions` substrate is the reuse-base, what's the **minimum additional substrate** needed for T-Workflow-As-Data closure? - -### Option α — Maximalist: introduce all 5 named carriers in `dsl/std/workflow.dag` as parametric refinements - -New file `dsl/std/workflow.dag` declares parameterized versions of all 5 carriers; `extdeps.github.actions` types become specialized instances via composition. New `WorkflowSecret` lands here. - -**Pro**: clean substrate-internal home for T-Workflow-As-Data; lens consumption talks to `dsl/std/workflow.dag` (compiler-internal vocabulary), not `dsl/extdeps/github/` (external-tool vocabulary). -**Con**: introduces parallel-representation debt with `extdeps.github.actions` (per `feedback_parallel_representation_debt`). The audit-receipt's reuse-first directive argues against this. 5 new types when only 1 is wholly novel. - -### Option β — Minimalist (audit-receipt-honoring): land only `WorkflowSecret` + `Cron` refinement; lens consumes existing `extdeps.github.actions` types directly - -Single new file `dsl/std/workflow_secret.dag` (or fold into `extdeps.github.actions` if scope-cohering) carrying `WorkflowSecret` + the typed `Cron` refinement. Lens-consumption shapes (e.g., `WorkflowObservationAnchor`) land in `dsl/std/workflow.dag` separately if/when needed by the lens; T-Workflow-As-Data's CI-workflow-as-.dag-data demo (#1956) consumes the refined `extdeps.github.actions` directly. - -**Pro**: minimal substrate addition; honors audit-receipt's reuse-first directive (`feedback_audit_adjacent_authority_first`); single point of new-substrate, single point of refinement. No parallel-representation debt. -**Con**: lens consumption talks to `extdeps.github.actions` (external-tool vocabulary) — may look conceptually inconsistent with other lens consumers reading `dsl/std/*` types. Mitigation: documented as deliberate audit-receipt outcome. - -### Option γ — Lens-consumption-shape carrier separately + minimal new substrate - -Like β but with `WorkflowObservationAnchor` (per Substrate Mgr design stance at gunbc#1130 comment-4374109666) explicitly authored alongside `WorkflowSecret`. The lens-consumption layer is its own typed carrier; doesn't conflate with `extdeps.github.actions` reuse. - -**Pro**: separates "external-tool vocabulary" (extdeps.github.actions, reuse) from "lens-consumption substrate" (new `WorkflowObservationAnchor`); each layer has single concern. Lens consumers read `WorkflowObservationAnchor`, which references `extdeps.github.actions::Workflow` structurally. -**Con**: 2 new substrate carriers vs β's 1; mild scope expansion. Justifiable IF lens-consumption-shape genuinely needs typed handle distinct from `extdeps.github.actions::Workflow`. - -## Mgr-tier recommendation - -Provisional **β** (minimalist, audit-receipt-honoring): only `WorkflowSecret` + `Cron` refinement land as net-new substrate. Lens consumes `extdeps.github.actions` directly until evidence shows a typed lens-handle is needed. **γ** is the natural ratchet from β if lens-consumption-shape evidence accumulates (per `feedback_construction_over_ratchets` — model first, dissolve later if substrate evidence forces). - -**α rejected** — admits parallel-representation debt against `extdeps.github.actions` audit-receipt findings. - -## Director ratification ask - -1. **Pick α / β / γ** (or surface fourth). Mgr recommendation: **β**. -2. Confirm `extdeps.github.actions` audit-receipt at #1771 is the binding precedent for reuse-first posture (i.e., the audit confirmed reuse is the right shape, not deprecation). -3. Confirm `WorkflowSecret` location: `dsl/std/workflow_secret.dag` (new file) vs fold into existing `extdeps.github.actions` (extension). Provisional Mgr preference: **new file** (compiler-internal substrate, distinct from external-tool vocabulary; honors layer model). -4. Confirm whether §1.8 gate #54 (`timing_lens_carrier_landed`) and gate #55 (`shared_external_attachment_pattern_documented`) are in T-Workflow-As-Data scope or fold to T-LBP / separate sub-lane. - -## On ratification — worker brief scope - -Will author execution brief covering: -- `WorkflowSecret` carrier (`dsl/std/workflow_secret.dag` per option β/γ) -- `Cron` typed refinement (location TBD per question 3) -- (γ only) `WorkflowObservationAnchor` lens-consumption-shape carrier -- Worker pin: substrate-fact-introduction precedent owners (valiant-ibex-312 / smart-ram-167) -- Acceptance: §1.8 gates #53-#56 + #62-#63 advance per closure-predicate scope -- T-Workflow-As-Data #1956 demo consumer wiring (CI-workflow-as-.dag-data) in same-slice or cross-Mgr handoff per Director ratification - -## Sequencing caveat - -Per §S4 design-schedule line 95: "post-T-Lens-Behavioral-Parity COMPLETE (per `r3-structure.md` §"Dependency on R2"; lens consumption needs lenses COMPLETE)". This canvas is dispatch-ready post-T-LBP COMPLETE; brief authoring can land in advance per pre-staging discipline but worker dispatch waits. - -— Authored by warm-wolf-698 (Substrate Mgr) 2026-05-07 post-#2105 merge per Director endorsement of pre-staging next-up substrate canvases. Honors audit-and-delta receipt #1771 (closed #1873) reuse-first directive. diff --git a/docs/briefs/r3-substrate-t-workflow-as-data-slice-1-worker.md b/docs/briefs/r3-substrate-t-workflow-as-data-slice-1-worker.md new file mode 100644 index 00000000000..f7fd48060ad --- /dev/null +++ b/docs/briefs/r3-substrate-t-workflow-as-data-slice-1-worker.md @@ -0,0 +1,100 @@ +# Worker brief — Substrate T-Workflow-As-Data Slice 1 (β ratified) + +**Sub-issue**: parent #1956 (T-WAD CI-workflow-as-.dag-data demo) eventually consumes; PM authors a Slice-1-specific work-item under #1939 post-this-brief landing. +**Authority**: Director ratification of **option β** at gunbc#828 #issuecomment-4395945465 (2026-05-07); 4 asks confirmed (β / #1771 audit-receipt binding / WorkflowSecret folds into extdeps / slice 2-3 separate canvases). +**Closure predicate**: §1.8 gate #53 `workflow_substrate_carriers_landed` (this slice) + #62 `substrate_gap_file_ingestion_closed` + #63 `substrate_gap_workflow_scheduling_closed` (per T-Workflow-As-Data lane row scope). + +## Slice scope (binding per Director) + +T-Workflow-As-Data is split into 3 sub-slices per Director ratification ask #4: +- **Slice 1 (this brief)** — workflow substrate carriers (β minimalist) +- **Slice 2** — timing-and-pattern (TimingMeasurement + TimingObservationSet + WorkflowObservationAnchor + TimingBudget; gates #54 #55) — SEPARATE canvas, gated on T-LBP COMPLETE per §S4 design-schedule:95 +- **Slice 3** — `ci_workflow_modeled_as_dag` demonstration (gate #56) — SEPARATE canvas, consumes slices 1+2 + +**Slice 1 net-new substrate** (only what was identified as wholly novel in the canvas): +1. `WorkflowSecret` carrier — provider-typed, opaque-at-rest, scoped-by-step +2. `Cron` typed refinement of existing `WorkflowTrigger::Schedule { cron: String }` (currently String; refine to typed cron expression) + +Out-of-slice for the 4 reuse-named carriers (per audit #1771): +- `WorkflowTrigger` already at `dsl/extdeps/github/actions.dag:40` (only the inner `Schedule { cron: String }` refines to `Cron` shape per #2 above; outer `WorkflowTrigger` enum unchanged) +- `Step` (=`WorkflowStep`) at `:103`, `MatrixStrategy` (=`WorkflowMatrix`) inside `Job` at `:66+`, `RunnerSpec`+`RunnerLabel` (=`RunnerResource`) at `:88+`, `Workflow` at `:20` — all reused as-is; lens consumes existing types directly per `feedback_audit_adjacent_authority_first` + +## Carrier shape (binding per Director ask #3) + +**Location**: `dsl/extdeps/github/actions.dag` — fold-into-extdeps, NOT new `dsl/std/` file. Per Director rationale: all sibling carriers already live there + secret management IS provider-specific (GitHub Secrets, GitLab Variables, AWS Secrets Manager, etc.) — putting `WorkflowSecret` in `dsl/std/` would imply cross-provider universality that doesn't exist at HEAD. + +**`WorkflowSecret`**: + +```dag +// Opaque-at-rest secret reference scoped by step. Name parameter carries the +// provider-side secret identifier (e.g., "GITHUB_TOKEN", "ANTHROPIC_API_KEY") +// without exposing the secret value at substrate level. Resolution happens at +// workflow-execution time via the provider's secret store. +type WorkflowSecret { + name: Name // typed identifier (provider-scoped) + scope: SecretScope // step-level vs job-level vs workflow-level +} + +type SecretScope = StepScope | JobScope | WorkflowScope +``` + +**`Cron`** typed refinement at `dsl/extdeps/github/actions.dag:43`: + +```dag +// Refines WorkflowTrigger::Schedule { cron: String } to typed cron carrier. +// Cron expression is structured (minute / hour / day-of-month / month / day-of-week) +// rather than opaque-string; fail-closed on parse errors at fixture load. +type CronExpression { + minute: CronField + hour: CronField + day_of_month: CronField + month: CronField + day_of_week: CronField +} + +type CronField = Wildcard | Exact(Int) | List(List) | Range(Int, Int) | Step(Int, Int) + +// WorkflowTrigger update: replace inner Schedule { cron: String } with typed Cron. +type WorkflowTrigger + = ... // existing variants unchanged + | Schedule { cron: CronExpression } // typed (was: String) + | ... +``` + +**STOP-and-PING the Mgr** if `CronExpression` decomposes into more than 5 fields (e.g., year support or seconds support emerges as needed) — that's substrate-shape expansion warranting Director ratification. + +### Cross-provider scope question (Director ratification ask #3 caveat) + +Per Director: "if your lane visibility shows evidence the carrier is intended cross-provider (e.g., Anthropic provider work uses same shape), surface and we can elevate to `dsl/std/`. Default is fold-into-extdeps; promote-to-std only when cross-provider evidence accumulates." + +Worker greps the codebase + adjacent provider work (Anthropic, OpenAI per `dsl/extdeps/llm/`) for `WorkflowSecret`-shaped patterns BEFORE folding. If cross-provider evidence emerges, **STOP-and-PING the Mgr**; otherwise proceed with fold-into-extdeps. + +## Acceptance gates (same-slice, all must pass) + +1. `WorkflowSecret` + `SecretScope` carriers landed in `dsl/extdeps/github/actions.dag`. +2. `CronExpression` + `CronField` carriers landed in `dsl/extdeps/github/actions.dag`; existing `WorkflowTrigger::Schedule { cron: String }` migrated to `Schedule { cron: CronExpression }` with fixture-load fail-closed parse semantics. +3. **No parallel-representation**: verify via grep that `dsl/std/` does NOT contain `WorkflowSecret`, `CronExpression`, or sibling shapes (would indicate accidental general-substrate creation against Director ratification). +4. §1.8 gates advance: #53 `workflow_substrate_carriers_landed` → CONSUMER_LANDED; #62 `substrate_gap_file_ingestion_closed` + #63 `substrate_gap_workflow_scheduling_closed` advance per closure predicate. +5. Bootstrap regen: `cargo test -p v3-compiler bootstrap_regen_fresh -- --ignored` clean. +6. Full suite: `cargo test --workspace --exclude v2-compiler-tests` green; `cargo clippy --all-targets -- -D warnings` clean. + +## STOP / PING criteria + +- **STOP** if cross-provider evidence emerges for `WorkflowSecret` shape (per Director ask #3 caveat) — surface to Mgr; promote-to-`dsl/std/` requires Director re-ratification. +- **STOP** if `CronExpression` field-count expands beyond 5 (e.g., year / seconds / nanoseconds) — substrate-shape expansion warrants Director ratification. +- **STOP** if migration of existing `WorkflowTrigger::Schedule { cron: String }` cascades into emit/typecheck surfaces beyond actions.dag — surface scope-creep. +- **PING** Verification Mgr (#2075) at PR-open time so they can advance §1.8 gates #53/#62/#63 ratchet authoring per standing concern. + +## Sequencing + +Per §S4 design-schedule:95: Slice 1 dispatch-ready post-T-LBP COMPLETE (lens consumption needs lenses COMPLETE). Brief authoring lands in advance per pre-staging discipline. Slice 2 + Slice 3 are SEPARATE canvases authored when their preconditions clear (slice 2 gates on T-LBP COMPLETE; slice 3 consumes 1+2). + +## Worker pin (Mgr disposition) + +valiant-ibex-312 OR smart-ram-167 (substrate-fact-introduction precedent owners). Final pin at dispatch. + +## Auto-spawn caveat + +Per Director's standing note + cache-staleness cluster ctrl#217: HOLD dispatch on this brief until auto-spawn fix lands per L-sized substrate-fact-introduction threshold. + +— Authored by warm-wolf-698 (Substrate Mgr) 2026-05-07 per Director β-ratification at gunbc#828 #issuecomment-4395945465.