Repository navigation
fix(v3): cap subtractive descent prover at producer's materialization range - #2201
Conversation
|
Review metadata
Verdict: APPROVE Diff is small and clean. The |
|
Approved under standing-authority — narrow +50/-4 scope; same single-authority discipline ( The Standing CI + sit-window applies; no Mgr review needed before merge. — sent from warm-wolf-698 |
briansrls
left a comment
There was a problem hiding this comment.
Review metadata
- Provider / model:
codex/unknown - Commit:
52e01e1f· Trigger:schedule - Thinking:
136s wall
✅ The change aligns the recursive termination prover with the producer’s bounded Peano materialization range and adds focused coverage for the former split-brain case.
|
Review metadata
1. Story of the diffThis PR closes a mismatch between the subtractive termination prover and the descent-evidence producer. Previously, 2. Invariant categories
Compliant — this is implementation-side lowering/prover logic, not a new substrate type or Dag schema change; the implementation explicitly reads the existing materialization authority via
Compliant — single-authority / fail-closed are handled by replacing the independent “positive integer” rule with the producer’s exact materialization range:
Compliant — the change stays in a small pure predicate: the local name changes from “positive” to the more precise
Compliant — the PR adds a focused regression test for the actual failure mode: the fixture uses
N/A — the diff does not add, remove, or alter any marked locked design decision; it aligns an implementation predicate with an existing materialization cap.
N/A — no new TODO, scaffold, bridge, temporary representation, or debt marker is introduced. The new comments at 3. VerdictAPPROVE The patch fixes the false-positive termination proof by making the subtractive prover consume the same bounded materialization authority as the descent producer, and it adds a targeted regression for the previously accepted oversize subtractor. I did not find a diff-line-backed invariant, coding-style, testing, locked-design, or debt issue. |
… range codex BLOCKING inline finding on (closed) PR #2198 surfaced a PRE-EXISTING parallel-authority issue on main, symmetric to the Slice 5 Div issue but for Sub: `is_strictly_smaller`'s Sub arm accepts any positive integer literal, but the per-call descent producer's `positive_amount_from_i64` only materializes `PositiveDescentAmount` for `1..=MAX_PEANO_MATERIALIZATION` (dag.rs:1031-1032). So `f(n - 257)` would pass termination while the producer fails to materialize and falls back to `SubValueUnknown` — same single-authority discipline violation Slice 3 (#2182) cemented for descent_provable / ClusterDescentChecker. This issue predates Slices 1-5; Sub was the only ArithmeticOp the prover accepted, and its acceptance boundary was never tightened to match the producer. closed PR #2198 was a Div extension; this fix is the symmetric Sub cap. Cap `is_strictly_smaller`'s Sub arm at the same `1..=MAX_PEANO_MATERIALIZATION` range as the producer's materialization. Both authorities now share the same acceptance boundary on `param - k`. New regression `..._constant_descent_termination_matches_producer_acceptance_boundary` pins the boundary by rejecting `n - 257` at compile time. If either authority shifts the range, this test surfaces the divergence — same tripwire shape as the indirect-call cementing test (#2200). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
52e01e1 to
bcf1198
Compare
|
Review metadata
Findings: None. The change uses the same Verdict: APPROVE — Small, targeted fix: cap |
|
Review metadata
1. Story of the diffThis PR fixes a split between two termination authorities for subtractive recursion. Before the change, 2. Invariant categories
Compliant — the diff does not introduce or mutate Dag-resident substrate types, fields, or variants; it is an implementation-side lowering/prover change that reads the existing materialization authority via
Compliant — fail-closed and single-authority are handled correctly:
Compliant — the implementation stays as a small pure helper decision: the local boolean is renamed to the more precise
Compliant — the PR adds a focused regression test for the behavioral bug: a minimal recursive fixture containing
N/A — the diff does not alter thesis/design documents or introduce a divergence from a locked design decision; it aligns an implementation helper to an existing materialization bound.
N/A — no new TODOs, temporary scaffolds, compatibility bridges, or staged alternate representations are introduced in the diff. 3. VerdictAPPROVE The patch is small and directly addresses the bug at the authority boundary: the prover now uses the producer’s existing materialization cap instead of independently accepting all positive subtractive literals. The regression test pins the oversize case that would previously have produced a false termination proof. |
Summary
Pre-existing parallel-authority fix surfaced by codex BLOCKING inline finding on (closed) PR #2198 (gunbc#2198 #pullrequestreview at 2026-05-08T02:28:36Z). Symmetric to the Div-cap fix that PR attempted but for Sub:
lower.rs::is_strictly_smaller's Sub arm accepts any positive integer literal (*v > 0)dag.rs::positive_amount_from_i64only materializesPositiveDescentAmountfor1..=MAX_PEANO_MATERIALIZATION(256)f(n - 257)therefore passes the termination prover but the producer falls back toSubValueUnknown— parallel-authority split-brainSame single-authority discipline Slice 3 (#2182) established for
descent_provable/ClusterDescentChecker. The discipline pattern Slices 1-5 have been holding the lane to.Provenance
This issue predates Slices 1-5. Sub was the only
ArithmeticOpthe prover accepted before Slice 5 attempted Div, and its acceptance boundary was never tightened to match the producer's materialization range. Closed PR #2198 attempted the symmetric Div cap; codex caught the asymmetric Sub gap during that review. PR #2198 was closed independently because v3's/returnsResult<T, DivError>(binary-halving recursion is unreachable at the v3 surface), so the Div cap was inert. The Sub cap is real and live.Mechanism
Same
MAX_PEANO_MATERIALIZATIONimport pattern (now used). Both authorities share the same acceptance boundary onparam - k.ClusterDescentCheckerautomatically inherits the change because its descent gate routes through the sameis_strictly_smallerpredicate (single-authority discipline preserved per Slice 3's BLOCKING-fix lesson).Tests
New:
e_p_per_call_descent_evidence_constant_descent_termination_matches_producer_acceptance_boundary— compilesf(n - 257)and asserts termination rejection. Symmetric tripwire to what closed PR #2198's boundary test established for Div.If either authority shifts the range (prover widens, producer narrows), the divergence surfaces immediately at this test.
Cross-slice invariants
CallPatternvariantSubValueRelationkindTransformNodewideningINVARIANTS.mdP1 substrate-fact-introduction triggerClusterDescentCheckerinherits via the shared predicate (P2 single-authority)Authority
lower.rs:8788)🤖 Generated with Claude Code