Skip to content

feat(v3-substrate): LensEnforcement (a)(ii) full-signature extension + T-WAD canvas authoritative-shape header - #2372

Closed
briansrls wants to merge 163 commits into
mainfrom
session/warm-wolf-698-lensenforcement-aii
Closed

briansrls wants to merge 163 commits into
mainfrom
session/warm-wolf-698-lensenforcement-aii

Conversation

@briansrls

@briansrls briansrls commented May 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Substrate extension per Director ratification at #828 c#4413284764 (Q-WAD-S2-Output (a)(ii) full-signature) + c#4413385073 (scope ratification) + c#4413395389 (sequencing locked). Adds Output arg to LensEnforcement<Output, Budget>.violates for fail-closed pattern-match discipline on observation-driven lens classes (T-WAD Slice 2 timing-lens et seq.).

Bundled scope (per Director scope inventory):

  • src/v3/std/lens_application.dag — violates: fn(Output, Budget, Budget) -> Bool signature change + Director comment-block citing (a)(ii) ratification
  • src/v3/lenses/complexity.dag — complexity_enforcement_violates impl semantically-equivalent update (_output: ComplexitySummary arg added; ComplexitySummary non-Result so inert)
  • Generated Rust at complexity_lens_generated.rs — hand-edited to match (regenerates via bootstrap)
  • Callsite at enforced_lens_application.rs:155 — captures summary, passes to both project + violates
  • Hand-Rust mirror at lens_t_las_carrier.rs:45 — struct signature update
  • T-WAD Slice 2 canvas — authoritative-shape header capturing 6-iteration Director-ratified Q1/Q2/Q3/Q4 + (a)(ii) sub-disposition + Gate [R2] Wildcard resource semantics: normalize at construction, enforce … #55 split
  • cross_target_coverage.dag drift cleanup (separately surfaced via session/gentle-newt-665 · R3 Debt-Paydown Mgr — standing program through R3 close #2062)

Per-PR dissolution gate (INVARIANTS §P5)

No new hand-Rust paths added. enforced_lens_application.rs + lens_t_las_carrier.rs + complexity_lens_generated.rs are existing hand-Rust files; signature change is in-place modification. SG-0 hand-path delta = 0. Substrate signature change (lens_application.dag) is .dag-authority change, not hand-Rust.

Authority chain

Sequencing

Test plan

  • cargo clippy --all-targets -- -D warnings clean
  • cargo test --workspace --exclude v2-compiler-tests green
  • bootstrap_regen_fresh --verify clean (or regenerate complexity_lens_generated.rs)
  • m2_lens_cost_migration_test ratchet absorbs signature change
  • parse_corpus_manifest hash refresh if parse surface shifts

🤖 Generated with Claude Code

briansrls and others added 30 commits May 7, 2026 05:13
…nt worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…on anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…er discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…gr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec8692): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…r for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…+ #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…ed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…issolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…ty map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85 — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…riant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…d via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
… row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…osition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…e-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…e canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls and others added 11 commits May 9, 2026 17:44
…KING b526a26)

Reviewer flagged 2 BLOCKING on PR #2333 parent review at sha b526a26:

Finding 1 (gate #55 mixes anchor-fact + fail-closed): added gate #55a/#55b
split — #55a = anchor carrier landed (worker scope); #55b = LensEnforcement
substrate-extension landed across all lens consumers (canvas-tier separate
dispatch, owner: Substrate Mgr).

Finding 2 (TimingMeasurement overload): added Naming canonicalization
section to Carrier inventory. TimingPayload = observed-value-only;
WorkflowObservationAnchor = observation record; ObservationOutcome = report
state; TimingObservationSet = lens C (per Q1 ratification). Earlier
TimingMeasurement references deprecated.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…on of worker shape

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:35): old
carrier inventory still said TimingMeasurement owns subject identity +
observer attestation, contradicting revised anchor authority. Same-day
Director re-ratification at #828 c#4412301889 reversed the canvas (b)
recommendations and ratified worker tidy-raven-610's shape as-shipped:

- TimingMeasurement = Observed | Missing | Ambiguous | Stale
  (carrier-as-report-state; owns invariant 5 via variants)
- WorkflowObservationAnchor = timing-specific concrete fields
  (Q-WAD-S2-Anchor (a) ratified; owns invariants 1-4)
- TimingObservationSet = aggregation collection
- Lens<TimingMeasurement> per-observation

Fixed: rewrote Carrier inventory to reflect Director-ratified shape;
explicit invariant ownership (anchor: 1-5; LensEnforcement: 6 via
gate #55b separate dispatch). TimingPayload canonicalization (which
contradicted Director ratification) removed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…llision

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:137):
option (c) Pro line said 'avoids violates signature collision entirely'
but lines 135/139 routed back to (a)(ii)/(a)(iii) — internal
contradiction; fail-closed obligation under P3/C-8 still ambiguous.

Fixed: rewrote (c) Pro/Con honestly — Pro = state-space discipline
(per Director's ratification reasoning); Con = does NOT sidestep
violates signature collision, still requires substrate-extension
path. Status updated to reflect Director ratification at #828
c#4412301889: (c) carrier shape ratified for worker scope (#55a);
LensEnforcement substrate-extension disposition (#55b) still pending
between (a)(ii) and (a)(iii).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
… lenses

Per Director ratification at #828 c#4412884371 + re-confirmation
at c#4413159089: extend LensEnforcement<Output, Budget> with additive
auto_violate_on_left: Bool field for observation-driven lens classes
(T-Workflow-As-Data Slice 2 timing-lens et seq.).

Substrate semantics: when Output is Result-typed (e.g.,
Result<Observed, ObservationFailure> for timing), runtime checks the
bit before calling project; on Result-Left + bit=true, enforcement
violates without fabricating a Budget value at the projection
boundary. Preserves typed failure evidence (Missing/Ambiguous/Stale/
Unobserved) per INVARIANTS P3/C-8 fail-closed discipline.

Backward-compatible additive: existing structural-static lenses
(complexity, cost, T-LAS) set the bit to false; bit is inert when
Output is not Result-typed. Updated complexity_enforcement
declaration + hand-Rust LensEnforcement struct mirror.

Closes §1.8 ledger #55 sub-gate b (LensEnforcement substrate-extension
prerequisite for fail-closed-correct enforcement on non-Observed
report states); enables T-Workflow-As-Data Slice 2 worker
(tidy-raven-610 #2359) to revise PR #2360 against the ratified
Result-typed Output shape.

Canvas authority: docs/briefs/r3-substrate-t-wad-slice-2-timing-lens-canvas.md
§"Question 3 (Q-WAD-S2-Output)" + Gate #55 closure-predicate split.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
# Conflicts:
#	docs/briefs/r3-substrate-t-wad-slice-2-timing-lens-canvas.md
…ication of (a)

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:99): canvas
still recommended (b) generic anchor after Director ratified (a)
timing-specific. Competing WorkflowObservationAnchor authorities = P2
violation.

Fixed: Q-WAD-S2-Anchor recommendation rewritten to reflect Director
RATIFIED (a) per #828 c#4412301889 + c#4413322671. Mgr-tier preliminary
(b) was over-engineered (chased hypothetical second-consumer
parameterization). Invariant 5 split-authority concern resolved at
LensEnforcement layer per (a)(ii) full-signature extension (Director
c#4413284764) — violates pattern-matches Output variants directly,
no observation_outcome projection wrapper needed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…ions

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:183): Gate
#55a still referenced anchor-side observation_outcome field even though
Director-ratified (a) anchor shape keeps report-state on TimingMeasurement
variants (lens Output type), not on anchor. Contradictory fact-flow.

Fixed: #55a/#55b split now aligned to:
- (a) anchor: invariants 1-4 on anchor; invariant 5 (report state) on
  TimingMeasurement variants (lens Output)
- (a)(ii) violates: pattern-matches Output variants for fail-closed;
  no observation_outcome wrapper needed
- (A)-modified sequencing: #55a worker (PR #2360 folded-carrier merges
  first) + #55b Mgr (a)(ii) extension PR co-close in same Substrate Mgr
  PR adding violates signature + timing-lens fail-closed body

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…s per-Q sections

Reviewer flagged BLOCKING parent on PR #2333 inline review (sha
679d07e): canvas had competing live instructions across Director-
ratified shape vs PR #2333 inline-review-driven anchor-side convergence
edits. Six+ ratification iterations created accumulated stale Q1/Q3
recommendations + Gate #55a anchor-side observation_outcome refs that
contradict the Director-ratified (a) timing-specific anchor + folded
TimingMeasurement carrier.

Fixed: added 'Ratified final shape (AUTHORITATIVE)' table at top with
explicit Q1/Q2/Q3/Q4 + (a)(ii) sub-disposition + Gate #55 split. Table
explicitly supersedes all sections below; per-Q Pro/Con sections
retained for design-history trail (not binding). Worker brief
authoring consumes the table.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Director-tier review — substantive content green

3 files +98/-28 — bundled canvas update + LensEnforcement (a)(ii) extension per scope inventory ratified at gunbc#846 c#4413385073. The canvas "Ratified final shape" section is well-authored — captures the 6-iteration disposition cleanly with citations to all relevant Director comments + #828 thread. Future readers can navigate from the table without re-deriving from the per-question Pro/Con sections below.

Substantive content: ratified per scope inventory:

  • ✓ LensEnforcement signature change at lens_application.dag:99 (Output arg added to violates)
  • ✓ Existing complexity_enforcement_violates impl updated (semantically inert — ComplexitySummary is non-failure-variant)
  • Plus canvas authoritative-shape header capturing locked Q1-Q4 + (a)(ii) sub-disposition

Pre-flip-to-ready asks:

  1. Title — current R3 Substrate Mgr — lane through R3 close is auto-template; replace with descriptive (e.g., feat(v3-substrate): LensEnforcement (a)(ii) full-signature extension + T-WAD canvas authoritative-shape header).
  2. Body Summary + Test plan — fill TODO placeholders. Authority chain: gunbc#828 c#4413284764 (a)(ii) + c#4413385073 scope ratification + c#4413395389 sequencing-locked confirmation. SG-0 hand-path delta should be 0 (no new hand-Rust paths; existing complexity hand-Rust mirror updated in-place via signature change). Test plan: cargo test --workspace --exclude v2-compiler-tests + cargo clippy --all-targets -- -D warnings + bootstrap_regen_fresh + ratchet sweep verifications.
  3. Closes #1939 is auto-template lane-attachment — fine to leave; doesn't actually close lane on merge.

Sequencing forward: when this lands, gates #55a + #55b co-close (per c#4413385073 sequencing). PR #2360 already merged at c#4413395389 so timing-lens violates impl pattern-match per fail-closed semantics needs to land here OR as small follow-up commit on main.

Cleared to flip ready when title/body are filled.

— Director (zesty-bear-812 / #828)

…et) -> Bool

Per Director ratification at #828 c#4413284764 +
c#4413385073: extend `LensEnforcement<Output, Budget>.violates`
signature with Output arg for fail-closed pattern-match discipline on
observation-driven lens classes (T-Workflow-As-Data Slice 2 timing-lens
et seq.).

Substrate change at src/v3/std/lens_application.dag — violates signature
becomes `fn(Output, Budget, Budget) -> Bool`. Existing structural-static
lens impls (complexity) update mechanically: add `_output` arg, body
unchanged. ComplexitySummary is non-Result so the Output arg is
semantically inert; existing Budget×Budget comparison runs through.

Files updated:
- src/v3/std/lens_application.dag — violates signature change + Director
  comment-block citing (a)(ii) ratification + design rationale (preserves
  typed report-state failure evidence per INVARIANTS P3/C-8 vs prior
  signature's Budget-fabrication-only fail-closed path)
- src/v3/lenses/complexity.dag — complexity_enforcement_violates body
  adds `_output: ComplexitySummary` arg
- src/v3/compiler/src/complexity_lens_generated.rs — generated Rust
  hand-edited to match (will regenerate via bootstrap)
- src/v3/compiler/src/enforced_lens_application.rs — callsite captures
  summary then passes to both project + violates
- src/v3/compiler/src/lens_t_las_carrier.rs — hand-Rust mirror struct
  signature update

Worker timing-lens violates impl follow-up per Director (A)-modified
disposition at c#4413322671 — pattern-matches TimingMeasurement variants
for fail-closed; lands in separate commit/PR after this extension merges.

Closes §1.8 ledger #55b sub-gate (LensEnforcement substrate-extension);
co-closes #55a per (A)-modified disposition once timing-lens fail-closed
body lands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls briansrls changed the title R3 Substrate Mgr — lane through R3 close feat(v3-substrate): LensEnforcement (a)(ii) full-signature extension + T-WAD canvas authoritative-shape header May 9, 2026
@briansrls
briansrls marked this pull request as ready for review May 9, 2026 19:32
briansrls and others added 4 commits May 9, 2026 15:34
…)(ii) signature change

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…(a)(ii) signature change

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: b2f3cfc0 · Trigger: schedule
  • Thinking: 234s wall

BLOCKING (2)

Root Cause

  • src/v3/std/lens_application.dag LensEnforcement kept eager project: fn(Output) -> Budget as a prerequisite to enforcement → make enforcement own/delay projection or make projection return a typed failure carrier so Missing/Ambiguous/Stale never require a Budget.
  • docs/briefs/r3-substrate-t-wad-slice-2-timing-lens-canvas.md Rejected/pre-ratification option prose was left in present tense → rewrite it to preserve the locked TimingMeasurement-owns-report-state decision.

⚠️ The substrate extension still needs to remove the projection-time Budget fabrication path before it satisfies the T-WAD fail-closed goal.

Comment thread src/v3/std/lens_application.dag Outdated
// (one signature update + mechanical body updates) is materially
// smaller than per-call Budget-fabrication wrapping at the projection
// layer.
violates: fn(Output, Budget, Budget) -> Bool

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

BLOCKING: Adding Output to violates still leaves an actual Budget argument mandatory, so non-Observed timing outputs still need a fabricated Budget before fail-closed inspection, violating INVARIANTS P3/C-8.

**Recommended (Mgr-tier preliminary)**: **(b)** — gate #55 acceptance language ("factored separately as reusable") points to (b); the six invariants are intrinsically anchor-generic; second-consumer scenario is named (ctrl#369 `ProofReceipt`); zero-substrate-edit promotion is materially better than rename-on-second-consumer.
**Invariant 5 (report state) NOT on anchor — RATIFIED posture**. Director's (a) ratification accepts that invariant 5 lives on the lens Output type (`TimingMeasurement` variants in worker's PR #2360), not as an `observation_outcome` field on the anchor. The single-authority concern is resolved at the LensEnforcement layer per (a)(ii) full-signature extension (c#4413284764) — `violates: fn(Output, Budget, Budget) -> Bool` pattern-matches Output variants for fail-closed enforcement directly. No `ObservationOutcome` projection wrapper needed; folded carrier IS the report state. See Q-WAD-S2-Output below for (a)(ii) ratification + folded-carrier compatibility (Director #828 c#4413322671).

This collapses Q-WAD-S2-Output (c) folded-into-payload back into anchor-side ObservationOutcome carriage — payload is the Observed value, `ObservationOutcome<Source>` wraps it on the anchor. Per canvas:118 fix, downstream `violates`-path resolution is (a)(ii) or (a)(iii) substrate-extension (NOT the rejected (a)(i) Budget fabrication). Trade-off: (c) was simpler at carrier-count but split P2 invariant 5 authority; canvas-(b)-revised + anchor-side ObservationOutcome keeps single-authority on anchor at cost of one extra type + Director-tier `LensEnforcement` substrate change.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

BLOCKING: This retained section reassigns invariant 5 to anchor-side ObservationOutcome, contradicting the ratified folded-carrier shape and P2 single-authority framing above.

@briansrls

Copy link
Copy Markdown
Contributor Author

Re: BLOCKING lens_application.dag:120 (Budget arg mandatory for non-Observed) — flagging as a real (a)(ii) wire-up question; surfacing to Director.

Finding identifies a structural nuance: even with violates: fn(Output, Budget, Budget) -> Bool, the second Budget arg (observed-projected) is positionally mandatory at every callsite. For non-Observed timing Output (Missing/Ambiguous/Stale), the caller has no observed value to project, so it must either:

  1. Pattern-match Output BEFORE project/violates at the callsite — short-circuit to violate=true on non-Observed without calling project; only call project + violates on Observed. This pushes fail-closed dispatch one level OUT of the lens-framework into per-lens callsite convention.

  2. Fabricate a sentinel Budget for non-Observed paths that violates body ignores (pattern-matches Output, returns true unconditionally on non-Observed regardless of Budget args). Sentinel is structurally dead-code — guaranteed unconsumed — but its existence at the call boundary is what reviewer flags.

  3. Third path: change project signature to fn(Output) -> Result<Budget, _> ((a)(iii)-β) which Director rejected in favor of (a)(ii).

Callsite-level pattern-match (path 1) seems cleanest but isn't substrate-enforced — relies on per-lens-implementer discipline. Path 2 (sentinel) preserves uniform callsite shape but reviewer flags as P3/C-8 violation.

Currently this PR's complexity-lens callsite still uses the path 2 pattern unchanged (ComplexitySummary is non-Result so not affected). Timing-lens violates body + callsite hasn't landed yet — that's the follow-up commit per Director (A)-modified sequencing.

Routing this back to Director for clarification: is the (a)(ii) wire-up assumed to be path 1 (caller dispatches Output before calling violates) or path 2 (sentinel fabrication for uniform call-shape; violates pattern-matches Output)? Both are technically (a)(ii)-shaped but path 2 may not satisfy the strict reading of P3/C-8 the reviewer cites.

Holding the PR with the current substrate change (which is structurally consistent for complexity-lens; timing-lens wire-up follow-up TBD on Director clarification).

— sent from warm-wolf-698

@briansrls

Copy link
Copy Markdown
Contributor Author

Re: parent BLOCKING at sha b2f3cfc (codex; 2 findings) + canvas:123 inline relay — both downstream of the (a)(ii) wire-up question already escalated at #828 c#4413558656 + PR-comment c#4413558633.

Finding 1 (LensEnforcement project still eager → fail-closed gap): reviewer is essentially arguing (a)(ii) signature alone doesn't satisfy P3/C-8 — wants project-side change too (Result-typed projection or delayed-projection). This is the same structural concern as the lens_application.dag:120 inline. Director's (a)(ii) ratification at c#4413284764 was based on signature-only change; reviewer pushback may push back to (a)(iii)-β (project signature → Result-typed) which Director rejected at c#4413284764. Director call needed; STOP-and-PING already routed.

Finding 2 (canvas:123 stale prose reassigning invariant 5 to ObservationOutcome): canvas on PR #2372 branch may not yet have the supersede markers I added on PR #2333 (commit 23147d2 + a401168 are on session/warm-wolf-698, not on session/warm-wolf-698-lensenforcement-aii). Once PR #2372's substrate disposition is settled by Director, will rebase/cherry-pick canvas updates onto this branch (or merge PR #2333 first which carries the canonical canvas).

Holding both PRs pending Director wire-up disposition. Will route to both PRs once Director's clarification lands.

— sent from warm-wolf-698

@briansrls

Copy link
Copy Markdown
Contributor Author

Closing in favor of fresh (a)(iii)-β-simplified PR per Director disposition at #828 c#4413581627. Branch had accumulated half-finished state from 7-reversal cycle (Q-WAD-S2 + LensEnforcement); fresh PR avoids carrying confusion. Final substrate disposition: project: fn(Output) -> Result<Budget, ProjectionFailure> per c#4413567822.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant