Skip to content

docs: reconcile cross_target_coverage emission_path_projections post-population drift - #2333

Merged
briansrls merged 168 commits into
mainfrom
session/warm-wolf-698
May 9, 2026
Merged

briansrls merged 168 commits into
mainfrom
session/warm-wolf-698

Conversation

@briansrls

@briansrls briansrls commented May 9, 2026 •

Copy link
Copy Markdown
Contributor

Comment-only fix: cross_target_coverage.dag:179 + sg0_census_test.rs:355 still described emission_path_projections as (empty data state) / == [], but the data block at cross_target_coverage.dag:186 is populated with 41 Phase-1 rows (Rust 13 / Python 16 / Go 12). P1 Modeling Faithfulness — comment-drift only, no behavior change.

Per-PR dissolution gate: no new or expanded hand-Rust. Comment-only edits to existing hand-Rust file (sg0_census_test.rs); no SG-0 census line shrink/grow. Per INVARIANTS §P5 Dispatch-Discipline (b), comment-only edits do not trigger dissolution-gate fill (no new authority, no new bridge).

Routing: Surfaced by gentle-newt-665 R3 Debt-Paydown ROADMAP audit at #2062. Absorbed into Substrate lane #1939 per L6 emission_path_projections carrier ownership.

🤖 Generated with Claude Code

briansrls and others added 30 commits May 7, 2026 05:13
…nt worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…on anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…er discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…gr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec8692): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…r for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…+ #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…ed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…issolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…ty map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85 — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…riant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…d via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
… row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…osition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…e-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…e canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…ions

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:183): Gate
#55a still referenced anchor-side observation_outcome field even though
Director-ratified (a) anchor shape keeps report-state on TimingMeasurement
variants (lens Output type), not on anchor. Contradictory fact-flow.

Fixed: #55a/#55b split now aligned to:
- (a) anchor: invariants 1-4 on anchor; invariant 5 (report state) on
  TimingMeasurement variants (lens Output)
- (a)(ii) violates: pattern-matches Output variants for fail-closed;
  no observation_outcome wrapper needed
- (A)-modified sequencing: #55a worker (PR #2360 folded-carrier merges
  first) + #55b Mgr (a)(ii) extension PR co-close in same Substrate Mgr
  PR adding violates signature + timing-lens fail-closed body

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Re: BLOCKING canvas:183 (Gate #55a anchor-side observation_outcome contradicts ratified TimingMeasurement-as-report-state) — addressed in commit 4310b30.

Finding is valid: Gate #55a split still referenced anchor-side observation_outcome field that contradicted Director-ratified (a) anchor shape (report-state lives on TimingMeasurement variants, not on anchor).

Updated split:

  • #55a (worker scope): anchor invariants 1-4 + carrier landing; invariant 5 on TimingMeasurement variants per Director (a) ratification.
  • #55b (Mgr scope): violates: fn(Output, Budget, Budget) -> Bool (a)(ii) signature change + timing-lens violates body pattern-matches TimingMeasurement variants for fail-closed (no observation_outcome wrapper needed).
  • Per Director (A)-modified disposition: gates co-close in the Mgr (a)(ii) extension PR once PR Substrate T-Workflow-As-Data timing-lens carrier (post-T-LBP COMPLETE) #2360 folded-carrier merges first. No separate #55b dispatch.

Canvas Gate #55 split now consistent with all ratifications: (a) anchor + folded-carrier output + (a)(ii) violates signature.

— sent from warm-wolf-698

…s per-Q sections

Reviewer flagged BLOCKING parent on PR #2333 inline review (sha
679d07e): canvas had competing live instructions across Director-
ratified shape vs PR #2333 inline-review-driven anchor-side convergence
edits. Six+ ratification iterations created accumulated stale Q1/Q3
recommendations + Gate #55a anchor-side observation_outcome refs that
contradict the Director-ratified (a) timing-specific anchor + folded
TimingMeasurement carrier.

Fixed: added 'Ratified final shape (AUTHORITATIVE)' table at top with
explicit Q1/Q2/Q3/Q4 + (a)(ii) sub-disposition + Gate #55 split. Table
explicitly supersedes all sections below; per-Q Pro/Con sections
retained for design-history trail (not binding). Worker brief
authoring consumes the table.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Re: BLOCKING parent review at sha 679d07e (codex) — addressed in commit 75c4168.

Finding is valid + structurally important: 6+ Director ratification iterations 2026-05-09 (Q3 reversed from worker-shape → Result-typed → back to folded; Q4 reversed; Q3 sub-disposition (a)(iii) → (a)(ii)) accumulated stale Q1/Q3 recommendations + Gate #55a anchor-side observation_outcome refs contradicting Director's final ratified (a) timing-specific anchor + folded TimingMeasurement carrier.

Fixed: added "Ratified final shape (AUTHORITATIVE)" table at top of canvas with explicit Q1/Q2/Q3/Q4 + (a)(ii) sub-disposition + Gate #55 (#55a worker / #55b Mgr) co-close path per (A)-modified disposition. Table explicitly supersedes per-question sections below. Per-question Pro/Con sections retained for design-history reasoning-trail (Mgr-tier preliminary → reviewer-corrections → Director ratification iterations) but NOT binding — worker brief authoring consumes the table.

This is the cleanest split between authoritative-disposition and reasoning-history; rather than rewriting all sections to match (which loses the iteration-history information that's been valuable for Director's calibration), the top-level table provides single-source-of-truth + lower sections preserve the discipline trail.

Cross_target_coverage drift cleanup substance unchanged (codex strengths confirmed both reconciliation edits).

— sent from warm-wolf-698

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 75c41689 · Trigger: schedule
  • Thinking: 188s wall

BLOCKING (2)

Root Cause

  • docs/briefs/r3-substrate-t-wad-slice-2-timing-lens-canvas.md Authoritative final-shape table was added while retained option sections still use live recommendation/ratification language → either delete the superseded branches or mark each contradictory branch explicitly historical/rejected and make all live closure text point only to the table’s ratified shapes.

Non-blocking — Strengths

  • src/v3/std/cross_target_coverage.dag The comment now matches the populated 41-row emission_path_projections data state.
  • src/v3/compiler/tests/integration/sg0_census_test.rs The SG-0 census rationale now matches the Phase-1 populated Rust/Python/Go row counts.

⚠️ The cross-target coverage cleanup is clean, but the timing-lens canvas still has two live contradictions against its own ratified final shape.

**Recommended (Mgr-tier preliminary)**: **(b)** — gate #55 acceptance language ("factored separately as reusable") points to (b); the six invariants are intrinsically anchor-generic; second-consumer scenario is named (ctrl#369 `ProofReceipt`); zero-substrate-edit promotion is materially better than rename-on-second-consumer.
**Invariant 5 (report state) NOT on anchor — RATIFIED posture**. Director's (a) ratification accepts that invariant 5 lives on the lens Output type (`TimingMeasurement` variants in worker's PR #2360), not as an `observation_outcome` field on the anchor. The single-authority concern is resolved at the LensEnforcement layer per (a)(ii) full-signature extension (c#4413284764) — `violates: fn(Output, Budget, Budget) -> Bool` pattern-matches Output variants for fail-closed enforcement directly. No `ObservationOutcome` projection wrapper needed; folded carrier IS the report state. See Q-WAD-S2-Output below for (a)(ii) ratification + folded-carrier compatibility (Director #828 c#4413322671).

This collapses Q-WAD-S2-Output (c) folded-into-payload back into anchor-side ObservationOutcome carriage — payload is the Observed value, `ObservationOutcome<Source>` wraps it on the anchor. Per canvas:118 fix, downstream `violates`-path resolution is (a)(ii) or (a)(iii) substrate-extension (NOT the rejected (a)(i) Budget fabrication). Trade-off: (c) was simpler at carrier-count but split P2 invariant 5 authority; canvas-(b)-revised + anchor-side ObservationOutcome keeps single-authority on anchor at cost of one extra type + Director-tier `LensEnforcement` substrate change.

This comment was marked as resolved.


- **Pro**: state-space discipline — carrier admits exactly the legal states (no illegal-state-via-projection-mismatch surface). Substrate carrier count is lower (no separate Output projection type). Per Director ratification reasoning (`feedback_no_rejected_patterns` + `feedback_state_space_vs_behavioral_invariants`): the carrier IS the coordinates the projection would have produced; folding dissolves an artificial separation.
- **Con (fail-closed structural)**: does NOT sidestep the `violates: fn(Budget, Budget) -> Bool` signature collision. `TimingMeasurement` variants reach `LensEnforcement.project: fn(Output) -> Budget` first; `violates` body cannot pattern-match the variants because the signature only sees the projected Budget. Per P3/C-8 fail-closed: non-Observed variants need typed-evidence preservation through to the violation-decision boundary, NOT Budget fabrication. **Therefore (c) STILL requires a substrate-extension path** — either (a)(ii) violates-signature extension or (a)(iii) auto-violate-bit on `LensEnforcement` — for fail-closed-correct enforcement on non-Observed.
- **Status**: **(c) RATIFIED by Director at #828 c#4412301889** as the carrier-shape disposition. Worker scope (gate #55a) lands the carrier shape; the substrate-extension for fail-closed-correct enforcement is **gate #55b** (separate Substrate-Mgr-scope dispatch; Director-tier sub-disposition between (a)(ii) and (a)(iii) still pending — see escalation thread at #828 c#4412879231 / c#4413178095).

This comment was marked as resolved.

briansrls and others added 2 commits May 9, 2026 19:38
…SUPERSEDED

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:123): old
convergence-path narrative still recommended folded-carrier 'collapses
back into anchor-side ObservationOutcome carriage' which contradicts
the authoritative ratified shape (invariant 5 on TimingMeasurement
variants; no anchor-side observation_outcome).

Fixed: marked the section explicitly SUPERSEDED by Director ratification
+ pointed to top-of-canvas ratified-shape table. Worker brief authoring
binds against the table, not the convergence-path narrative which is
historical reasoning trail.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…pending language

Reviewer flagged BLOCKING canvas:158: stale 'sub-disposition between
(a)(ii) and (a)(iii) still pending' contradicted authoritative table
+ Gate #55b text both ratifying (a)(ii). Plus other (a)(ii) or (a)(iii)
refs at canvas:112.

Fixed: replaced all '(a)(ii) or (a)(iii)' refs with '(a)(ii)' (Director
ratified at c#4413284764). Q3 status line now explicitly cites (A)-modified
sequencing + (a)(ii) sub-disposition + canvas authoritative table as
binding.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Re: BLOCKING canvas:123 (anchor-side ObservationOutcome convergence) + canvas:158 ((a)(ii)/(a)(iii) pending language) + parent BLOCKING at sha 75c4168 (live contradictions vs ratified table) — addressed in commits 23147d2 + a401168.

Both inline findings + parent finding stem from the same root: per-question Pro/Con sections retained live recommendation/ratification language even after the authoritative table at canvas top was added. Fixed:

  • canvas:123 — "(c) folded-into-payload back into anchor-side ObservationOutcome carriage" → marked SUPERSEDED with explicit pointer to top-of-canvas table (commit 23147d2)
  • canvas:158 — Q3 sub-disposition status line now cites (A)-modified sequencing + (a)(ii) ratification (commit a401168)
  • All "(a)(ii) or (a)(iii)" refs replaced with "(a)(ii)" (Director ratified at c#4413284764)

Worker brief authoring binds against top-of-canvas "Ratified final shape" table; per-question sections now consistently point to the table as binding rather than asserting their own recommendations. Codex strengths on cross_target_coverage cleanup confirmed clean.

— sent from warm-wolf-698

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: a4011685 · Trigger: schedule
  • Thinking: 292s wall

BLOCKING (1)

Root Cause

  • docs/briefs/r3-substrate-t-wad-slice-2-timing-lens-canvas.md Gate #55 current-state wording and future closure predicate were merged in one section → make #55b consistently future tense until the LensEnforcement signature PR actually lands, or cite the actual landed carrier authority.

⚠️ One live gate-state contradiction remains in the timing-lens canvas.

Per PR #2333 inline review at canvas (b526a26f finding 1): gate #55 mixes anchor-fact-carriage with fail-closed semantics. Split:

- **Gate #55a** (anchor-fact-carriage): `WorkflowObservationAnchor` declared with invariants 1-4 as concrete fields (subject identity / artifact digest / producer-observer-prover identity / attachment timestamp + run id) per Director-ratified (a) timing-specific shape. Invariant 5 (report state Observed/Missing/Ambiguous/Stale) lives on the lens Output type `TimingMeasurement` variants, NOT on the anchor — single-authority preserved at the lens layer (consumed by `violates` per (a)(ii)). Closes when worker carrier lands per PR #2360.
- **Gate #55b** (fail-closed enforcement): `LensEnforcement` substrate-extension landed per Q-WAD-S2-Output (a)(ii) Director ratification at #828 c#4413284764 — `violates: fn(Output, Budget, Budget) -> Bool` signature change cascading across T-LBP / T-CostLens / T-LAS impls (semantic-equivalent updates) + timing-lens `violates` body pattern-matches `TimingMeasurement` variants, returning true for Missing/Ambiguous/Stale (fail-closed without Budget fabrication, preserving typed report-state evidence per P3/C-8).

This comment was marked as resolved.

@briansrls

Copy link
Copy Markdown
Contributor Author

Re: BLOCKING canvas:200 (#55b past-tense vs future-PR posture) — addressed in commit 59ca997 (auto-WIP).

Updated Gate #55b language:

Canvas now consistent with current substrate disposition. Worker brief authoring binds against the top-of-canvas ratified-shape table; #55b language honestly reflects PENDING state.

Quick ack on parallel PR ops:

— sent from warm-wolf-698

…d-with-(β)-bespoke

cursor/composer-2 REQUEST_CHANGES on PR #2333: top authoritative table
still bound (a)(ii) for Q3 + Gate #55b while lower split section
described (a)(iii)-β-simplified — two incompatible instructions per P2
single-authority. Director ratified (β) bespoke ProjectionResult at
#828 c#4413663658 (final lock); top table updated to match.

Q3 sub-disposition + Gate #55b now consistent: (a)(iii)-β-simplified-
with-(β)-bespoke ProjectionResult; PR #2400 in-flight; lens-rust-emit
MissingTypeRealization Path 1 canvas-tier resolution per c#4413702193.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Re: cursor/composer-2 REQUEST_CHANGES — addressed in commit 926c4c4.

Top authoritative table Q3 sub-disposition + Gate #55b reconciled to (a)(iii)-β-simplified-with-(β)-bespoke ProjectionResult (final Director ratification at #828 c#4413663658). Reversal trail explicitly documented in table cell:

  • (a)(ii) at c#4413284764 → REVERSED
  • (a)(iii)-β at c#4413567822 → SUPERSEDED by emit-mismatch
  • (a)(iii)-β-simplified-with-(β)-bespoke at c#4413663658 → LOCKED

Gate #55b reflects PR #2400 in-flight + lens-rust-emit MissingTypeRealization Path 1 canvas-tier resolution per c#4413702193.

Top table + Gate #55 closure-predicate split now consistent. P2 single-authority restored.

— sent from warm-wolf-698

…le P1/P2

cursor/composer-2 REQUEST_CHANGES on PR #2333: top table locks
(a)(iii)-β-simplified-with-(β)-bespoke but lower sections at :112
:121 :148 :158 :199 still treated (a)(ii) as ratified/pending —
INVARIANTS P1 (live state) + P2 (single authority) violation.

Fixed: prepended [SUPERSEDED — top table is authoritative] markers to
each (a)(ii) reference; updated where final shape clarification helps.
Top table remains authoritative; lower sections are explicitly
historical-reasoning-trail.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Re: cursor/composer-2 REQUEST_CHANGES on canvas (a)(ii)/top-table contradictions — addressed in commit ea3115b.

Marked all lower (a)(ii) references with [SUPERSEDED — top table is authoritative] prefix:

  • canvas:112 (timing instantiation discussion)
  • canvas:121 (invariant 5 RATIFIED posture)
  • canvas:148 (Output sub-disposition recommendation)
  • canvas:158 (Status line)
  • canvas:193 (six invariants list — invariant 6 entry)
  • canvas:199 (Gate #55a — clarified to use (a)(iii)-β-simplified terminology)

Top table at :21-36 remains the binding authority; lower sections are explicitly historical-reasoning-trail with SUPERSEDED markers per INVARIANTS P1 (live state) + P2 (single authority).

— sent from warm-wolf-698

briansrls and others added 3 commits May 9, 2026 18:11
…NOT DSL Result)

cursor/composer-2 commented on PR #2333: canvas:35/200/202 still used
'Result-typed signature' / 'fn(Output) -> Result<Budget,
ProjectionFailure>' wording while top table locks bespoke
ProjectionResult<Budget> = ProjectedBudget | ProjectionFailed (NOT
DSL stdlib Result). P2 single-authority at risk for readers following
those sections.

Fixed: canvas:35 + canvas:200 + canvas:202 now consistently cite
bespoke ProjectionResult<Budget> shape with explicit 'NOT DSL stdlib
Result' marker. Reversal trail c#4413284764 → c#4413567822 →
c#4413663658 preserved. Framework apply pattern updated to use
ProjectedBudget { value } / ProjectionFailed { _ } variant pattern-
matching.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Re: cursor/composer-2 findings on canvas:35/200/202 (Result vs ProjectionResult naming) — addressed in commit 6bd5294.

All three lines now consistently cite bespoke ProjectionResult<Budget> shape with explicit 'NOT DSL stdlib Result' marker. Framework apply pattern updated to ProjectedBudget/ProjectionFailed variant matching. Reversal trail preserved (c#4413284764 → c#4413567822 → c#4413663658).

Non-blocking observation on canvas:133 (modeling-discipline.md citation scope) noted — modeling-discipline ties 🟢/🟡/🔴 to Rust enums; .dag sums may be over-read. Captured for future canvas-cleanup; not blocking this PR.

— sent from warm-wolf-698

@briansrls
briansrls merged commit 6557ded into main May 9, 2026
4 checks passed
@briansrls
briansrls deleted the session/warm-wolf-698 branch May 9, 2026 22:53

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 861dc667 · Trigger: schedule
  • Thinking: 210s wall

BLOCKING (1)

Root Cause

  • docs/briefs/r3-substrate-t-wad-slice-2-timing-lens-canvas.md LensEnforcement extension resolved the std Result emit mismatch by naming a bespoke carrier without a substrate-discipline receipt → either reuse std.error_primitives Result or mark ProjectionResult as a tracked scaffold with the concrete emit-mismatch dissolution trigger before PR #2400 authors it.

⚠️ One new substrate coproduct needs a P5/M9 receipt before this design can safely dispatch the worker shape.

| **Q-WAD-S2-Anchor** | (a) timing-specific concrete fields on `WorkflowObservationAnchor` (NOT (b) generic parametric) — 4 invariants on anchor (subject_stable_id / artifact_digest / producer-observer-prover / attached_at + run_id); promotion to ProofReceipt-second-consumer is bounded refactor | #828 c#4412301889 + c#4413322671 |
| **Q-WAD-S2-Output** | folded carrier `TimingMeasurement = Observed { nanoseconds: Int } \| Missing \| Ambiguous \| Stale` (NOT separate-projection sum, NOT Result-typed). Carrier IS the report-state. Invariant 5 lives on TimingMeasurement variants. | #828 c#4412301889 + c#4413322671 (A-modified) |
| **Q-WAD-S2-Placement** | `src/v3/std/timing_lens.dag` per `src/v3/std/lens.dag:17-21` v3-only-carriers convention (NOT `dsl/std/`) | #828 c#4413159089 |
| **Q3 sub-disposition (LensEnforcement extension)** | (a)(ii) full-signature change: `violates: fn(Output, Budget, Budget) -> Bool` (NOT (a)(i) Budget fabrication; NOT (a)(iii) auto-violate-bit). `violates` body pattern-matches Output variants for fail-closed without Budget fabrication. | #828 c#4413284764 |

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

BLOCKING: The locked ProjectionResult bespoke sum is substrate-facing but neither uses existing std.error_primitives Result nor carries a 🟢/🟡/🔴 dissolution receipt/named trigger, so P5/M9 would dispatch an untracked duplicate result coproduct.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant