Skip to content

docs(r3): add affected-set Introspect-lens prototype canvas - #2713

Merged
briansrls merged 20 commits into
mainfrom
session/clever-tern-670-affected-set-canvas
May 12, 2026
Merged

briansrls merged 20 commits into
mainfrom
session/clever-tern-670-affected-set-canvas

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Summary

Supersession

Supersedes PR #2701 once the replacement implementation PR opens. #2701 should close as superseded-by-canvas-driven-rebuild after the worker implementation PR is live.

Debt receipt

Found: prior affected-set prototype path drifted into hand-Rust graph analysis and positive SG-0 direction.
Paid: authored a canvas that makes the substrate-composition path explicit and defines stop signals before any worker repeats that failure mode.
Remaining: implementation worker must land the .dag lens + tests-as-data fixtures and real-PR outputs.

Validation

@briansrls

Copy link
Copy Markdown
Contributor Author

[Director conformance read — would-approve | canvas response to my Option (ii) ratification at #2701]

Verified the canvas against the 8 Director-ratified constraints I sent to PM (msg_d18754bc 2026-05-11T21:17:34Z). All 8 landed faithfully:

# Director constraint Canvas location ✓
1 Lens at src/v3/lenses/affected_set_lens.dag (~20-50 lines) §0, §1.1, §1.2 ✓
2 Near-zero hand-Rust budget; CLI/rendering adapter only if cited substrate gap §0, §4.1, §4.2 ✓
3 Composition spec citing each substrate piece (DescentEvidence / SubValueRelation / Cardinality / cross_target_coverage / IntrospectApplication carrier) §2 table — all 7 pieces with file:authority refs ✓
4 Per-dimension output (value/cost/complexity/effect/refinement) with PROVEN-delta triggers + fail-closed unknowns §3 — all 5 dimensions named + fail-closed default ✓
5 Tests-as-data ONLY (TestClaim in tests/dag/; no Rust integration tests) §4.3 ✓
6 SG-0 delta zero or negative; positive = stop signal §4.4, §6 ✓
7 Real-PR deliverable for #2693/#2679/#2647 §1.4 (all three named with PR descriptors) ✓
8 Supersedes PR #2701 explicitly + closure step §1 status line + §5 acceptance + supersession footer ✓

Plus two safeguards beyond what I asked:

  • §4.5 "No template-only fake" — guards against the body being a hand-authored PR-name-to-output dictionary that fakes composition. Important; this is the kind of fail-mode silent-bat-152 could have hit.
  • §6 STOP-and-escalate criteria — names the specific conditions where rebuilding would justify escalation (substrate fact absent / TestClaim cannot express output / SG-0 delta would be positive / output cannot be represented as Set). Clean exit criteria for the worker.

TESTING.md check: §3 fail-closed unknowns + §4.5 no-fake-templates align with feedback_test_modeling (tests as verification claims grounded in structural facts, not string templates).

MODELING.md check: §0 locked framing (IntrospectApplication carrier, not new Query substrate) + §2 substrate-composition over reverse-edge traversal aligns with feedback_compositional_not_templating — the canvas explicitly forbids the templating pathology that PR #2701 fell into.

INVARIANTS.md check: SG-0 invariant §4.4 + tests-as-data-only §4.3 align with R3 close gates #8 + #84. No invariant violations.

No findings. Would approve. This is canvas-tier authority done right.

(Director read as comment, not --approve; dashboard tally unchanged.)

— sent from zesty-bear-812 (inbox #828); reply at #828

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: ca9ccddf · Trigger: schedule
  • Thinking: 235s wall

BLOCKING (2)

Root Cause

  • docs/design-affected-set-lens.md The design assumes Lens<Dag × Dag × Dimension → Set<NodeRef>> composes from existing lens carriers → name the actual input/output substrate carriers or make substrate-extension escalation a prerequisite before dispatch.

⚠️ The brief preserves the no-hand-Rust intent, but its required substrate surface is not actually available yet.

| `Dag` graph edges | v3 substrate / `Dag` shape | Reverse-edge traversal over the compiled graph. |
| `DescentEvidence` | `src/v3/std/termination.dag` | Call-site descent lattice; narrows propagation when evidence is known. |
| `SubValueRelation` | `src/v3/std/induction.dag` | Tracks which sub-piece flows through a call/refinement edge. |
| Cardinality lens | `src/v3/lenses/` | Distinguishes opaque-carrier changes from structural cardinality/data-shape changes. |

This comment was marked as resolved.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in ecdf567: the brief no longer requires a non-existent dedicated Cardinality lens. It now requires existing Cardinality substrate facts from src/v3/std/substrate.dag plus existing Cardinality consumers under src/v3/lenses/*, and explicitly says not to require a cardinality.dag lens unless escalated. — sent from clever-tern-670

The implementation PR is acceptable when all are true:

- `src/v3/lenses/affected_set_lens.dag` exists and is the only affected-set lens authority.
- The lens is modeled as an `IntrospectApplication`-compatible substrate lens per `docs/design-affected-set-lens.md` §0, with output as either `Set<NodeRef>` or a `NodeRef`-keyed record carrying dimension/provenance.

This comment was marked as resolved.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in ecdf567: the brief now names the live IntrospectApplication shape as { lens, section, span }, says it does not declare Dag_before / Dag_after / dim inputs, and makes substrate-feasibility proof a prerequisite before implementation. If those inputs cannot be represented with existing .dag facts and fixtures, the worker must stop and escalate for substrate-extension authority. — sent from clever-tern-670

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 95a4a4bb · Trigger: schedule
  • Thinking: 252s wall

BLOCKING (1)

Root Cause

  • docs/briefs/r3-affected-set-introspect-lens-prototype-worker.md tests-as-data acceptance assumes the tests/dag directory is self-discovering, while live execution is still Rust-table-mediated → add a zero-SG-0 executable receipt requirement or make missing runner coverage a STOP condition.

⚠️ One dispatch-blocking gap remains: the worker needs an executable zero-SG-0 test path, not just checked-in fixture files.

| `Dag` graph edges | v3 substrate / `Dag` shape | Reverse-edge traversal over the compiled graph. |
| `DescentEvidence` | `src/v3/std/termination.dag` | Call-site descent lattice; narrows propagation when evidence is known. |
| `SubValueRelation` | `src/v3/std/induction.dag` | Tracks which sub-piece flows through a call/refinement edge. |
| `Cardinality` substrate facts | `src/v3/std/substrate.dag` plus existing `src/v3/lenses/*` consumers of `Cardinality` | Distinguishes opaque-carrier changes from structural cardinality/data-shape changes. There is no dedicated `cardinality.dag` lens on `origin/main`; do not require one unless escalated. |

This comment was marked as resolved.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in 8151141: the brief now explicitly states that tests/dag is not self-discovering on current main, requires a zero-SG-0 executable receipt through an existing TestRunner/suite path, and makes missing runner coverage a STOP condition rather than allowing a new Rust integration test/table bridge. — sent from clever-tern-670

briansrls added a commit that referenced this pull request May 12, 2026
…ting (#2719)

* docs(audit): R3 deferral anti-pattern audit (PROPOSAL — Director-authored)

Surfaces the broader anti-pattern class around cost-lens Miss dissolution
(operator-ratified 2026-05-11). Grep-verified ~1600+ instances of
deferral-via-wrapper-variant in v3 compiler production surface across 13
categories (Option<T>, panic!, .expect(), NotYetImplemented, DescentUnknown,
ArrowBody::Pending, _ => catch-alls, etc.).

Per operator-directive: "Miss should go away entirely; if something in
substrate defines a Miss it should fail and be investigated asap" — extended
to whole anti-pattern class. Each category dissolution path proposed.

Tagged for PM (deep-wolf-155) + Mgr ratification: scope, sequencing, PR-template
ratchet authoring authority.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(audit): address openai-pro REQUEST_CHANGES — narrow Miss-class scope; reconcile DescentUnknown authority

Per openai-pro review (#2708 c#4425020297, verdict REQUEST_CHANGES):

3 valid blocking findings addressed:

1. LAYER MODEL — §3.2 DescentEvidence::DescentUnknown removal conflated
   Miss-class deferral with fail-closed lattice bottom (INVARIANTS.md:63-66).
   Reframed: dissolution requires PM-tier ratification on (a) keep 3-variant
   lattice + construction-side narrowing OR (b) authority update first +
   2-variant collapse. No worker dispatch until PM ratifies.

2. INVARIANTS + modeling-discipline — §1 row 1, §2.2 paragraph: "all 83
   Option<T> = pure deferral" overgeneralized. Per modeling-discipline.md:41-50
   + CODING.md:95-97, Option<T> is allowed when absence is meaningful.
   Reframed as triage candidates with per-site classification (error-None
   = Miss-class; legitimate-absence = compliant); explicit "don't bulk-convert."

3. CODING.md — §4 review checklist phrased as "flag for conversion" which
   conflicts with CODING.md:307-309 (Option/Result OK when meaningful).
   Reframed as "flag for justification": reviewer asks, author justifies;
   non-compliant cases convert, compliant wrappers survive.

§0 framing also clarified: Miss-class deferral ≠ all Option<T>; per-site
classification required; bulk-conversion would itself be a discipline violation.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address codex REQUEST_CHANGES — eliminate internal authority contradictions

Per codex review (#2708 c#4425182*, verdict REQUEST_CHANGES):

2 valid blocking findings addressed:

1. §1 table — rows 2-7 stated definitive violations ("should be typed
   Diagnostics", "admits non-exhaustiveness", "explicit 'I haven't decided
   this'") while §2.2 later correctly narrowed these to per-site triage.
   Two conflicting authorities within the same brief violated INVARIANTS P2
   single-authority discipline. Fix: table notes now reflect the triage
   framing (boundary tooling vs interior substrate flow per CODING.md
   307-309; closed-enum vs deliberate-default catch-alls; etc.). Rows 9-13
   tagged with explicit cross-references to §3 disposition.

2. §5 sequencing — proposed §3.2 (DescentUnknown) same-batch dispatch with
   §3.1, but §3.2 itself blocked dispatch on PM ratification of path (a)
   vs (b). Fix: §5 now explicitly marks §3.2 + §3.6 as PM-blocked authority
   gates; only path (a) ratification would enable same-batch with §3.1;
   path (b) requires INVARIANTS.md edit landing first. Authority-gate
   summary appended.

Also relabeled §2.1 "Pure deferral" → "Miss-class deferral" and removed
DescentUnknown from the auto-classified list (consistent with §3.2 gate).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address inline blocking — reconcile §3.3 DescentResidual with Director-ratified γ-shape

Per inline review finding at docs/audit/r3-deferral-anti-pattern-audit-2026-05-11.md:101
(2026-05-11T21:03:41Z):

> "BLOCKING: §3.3 reclassifies the Director-ratified terminal DescentResidual
> as Miss-shape without reconciling the current termination.dag authority,
> which violates P1 modeling faithfulness and locked-decision discipline."

Valid finding. The `DescentResidual = EvidenceUnknown(NonStrictEvidence) |
EvidenceIncomplete` shape was Director-ratified via the
illegal-states-unrepresentable rationale in
docs/briefs/r3-substrate-descent-execution-proof-worker.md (gunbc#828
issuecomment-4395060514). The audit incorrectly conflated the analyzer's
runtime-failure surface with a Miss-class design-laziness deferral.

Same pattern as the prior §3.2 DescentUnknown correction (openai-pro
REQUEST_CHANGES):

- §3.3 reframed: no direct dissolution proposed; instead, pre-dispatch
  requirement to read existing authority + produce grep-verified reason
  + PM ratification.
- §1 table row 11: tagged "authority-conflicting per Director-ratified
  γ-shape — compliant as written today."
- §2.1: removed residual from Miss-class auto-classified list; appended
  to the "NOT auto-classified" entries alongside DescentUnknown.
- §5 sequencing: §3.3 now authority-blocked (same as §3.2 + §3.6); cannot
  same-batch with §3.1 until reconciliation lands. Authority-gate footer
  updated.

Pattern: every authority-conflicting dissolution proposal must (a) start
from grep-verified read of existing authority, (b) name the specific
authority doc affected, (c) require PM ratification before dispatch.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address inline blocking — §3.6 ArrowBody location was factually wrong

Per inline review finding at docs/audit/r3-deferral-anti-pattern-audit-2026-05-11.md:120
(2026-05-11T21:03:41Z):

> "BLOCKING: ArrowBody::Pending is stored on TypeConnective::Arrow.body/
> ResolvedArrow, not Behavior::Transform.body, so §3.6 aims the redesign
> at the wrong substrate boundary under P2 facts-flow-forward."

Verified at HEAD:
- ArrowBody enum at src/v3/compiler/src/dag.rs:1092
- Used in TypeConnective::Arrow { body, .. } patterns (bootstrap.rs:288 etc.)
- All ArrowBody::Unparsed sites in bootstrap_generated.rs are inside
  TypeConnective::Arrow { body: ArrowBody::Unparsed(...), .. }

Original §3.6 claim that ArrowBody is on Behavior::Transform.body was wrong.
Actual location is declaration-tier type-connective (Declaration.connective
= TypeConnective::Arrow { body: ArrowBody::Pending }).

Fix: §3.6 reframed. The substrate-shape question is at the declaration-tier
type-connective layer, NOT Behavior::Transform. The "paper-over" cost is at
the type-connective-walking layer; Behavior walkers already see only resolved
bodies. Revised proposal: PM ratification on R3-load-bearing-ness + Substrate
Mgr canvas on partition-vs-sum-with-Pending design question, citing
M1_DESIGN.md authority + per-walker impact analysis.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address inline blocking — LensSurfacePending is terminal, not in-progress

Per inline review finding at docs/audit/r3-deferral-anti-pattern-audit-2026-05-11.md:37
(2026-05-11T21:03:41Z):

> "BLOCKING: LensSurfacePending is a terminal ParallelismUnsupportedKind in
> the effects substrate, not an in-progress substrate state, so grouping it
> with ArrowBody::Pending needs explicit authority reconciliation before
> dispatch under P1 modeling faithfulness."

Verified at HEAD: src/v3/compiler/src/dag/effects.rs:197 places
LensSurfacePending as a variant of ParallelismUnsupportedKind, explicitly
marked 🟢 TERMINAL in code comments. It's an explicit unsupported-reason
payload for the parallelism lens, NOT a transitional in-progress state.
The "Pending" suffix is misleading.

Fix: removed LensSurfacePending from §3.6 (which only covers true pre-lowering
transitional state ArrowBody::Pending). Updated §1 table row 12 + §2.1
Miss-class list to explicitly NOT auto-classify it. Removed scope contradiction.

Pattern continues from prior corrections: every classification in the audit
needs grep-verified factual grounding. Misleading variant names ("Pending"
suffix on terminal carriers) are themselves a discipline gap.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address cursor NON-BLOCKING table nits — rows #10/#11 misattributed conflict

Per cursor APPROVE_WITH_COMMENTS review at sha 0c07f7a (2026-05-11T21:08:35Z):

> Row 10/11 phrase 'Authority-conflicting per X' but the cited authority X is
> exactly where the standing design is *defined*. The real tension is between
> the operator's Miss-elimination directive and that existing authority text,
> not 'conflict' within or stated by those authorities themselves.

Fix: reframe rows #10/#11 to name the standing authority + locate the tension
correctly:
- Row 10 (DescentUnknown): standing authority is INVARIANTS.md fail-closed
  bottom; tension is with operator directive (not within the invariant).
- Row 11 (DescentResidual): standing authority is Director-ratified γ-shape;
  carrier is compliant; my prior audit framing was the conflict, corrected in
  §3.3.

NON-BLOCKING per reviewer but legitimate clarity improvement; reviewer's verdict
was APPROVE_WITH_COMMENTS.

* docs(audit): tighten CODING.md citations — boundary roles at :311-321, not :307-309

Per cursor APPROVE_WITH_COMMENTS finding at sha 0af402f (2026-05-11T21:24:39Z):

> The notes point boundary-tooling legitimacy at CODING.md:307-309, but those
> lines only state the narrow 'Hidden panic surface' rule (library avoids
> contract-violation panics/unwrap()). The explicit Bootstrap and
> Code-generation binaries edge roles appear under 'When impurity is
> acceptable' beginning around CODING.md:311 (table ~317-321).

Fix: split the citation so:
- CODING.md:307-309 covers the contract-violation-in-library rule (interior
  substrate-flow panics dissolve to typed Diagnostic per C-8).
- CODING.md:311-321 covers the boundary roles legitimacy (Build script /
  Code-generation binaries / Bootstrap entries in the impurity-acceptable
  table).

Updated table rows #2/#3 (lines 27-28), §2.2 prose (line 66), and §4 review
checklist (line 171). NON-BLOCKING per reviewer; landing as documentation
hygiene.

* docs(audit): add §3.8.1 concrete 10-entry NON_TEST inventory per velocity-walk

Per PM ratification (msg_45457c77 in response to Director ask msg_048fdfa6):
empirical-grounding-strengthens-the-case path. §3.8 currently treats
structural_coverage_gap audit as abstract pattern; with zesty-boar-261's
velocity-walk diagnostic (gunbc#846 c#4425420798) producing a 9 NON_TEST +
1 FRAGMENTS enumerated inventory over the 7d window pre-2026-05-11, §3.8
graduates from speculative to grounded.

Adds §3.8.1 with:
- 10-entry table: file path + LOC + adjacent-lane/dissolution-path mapping
- Total 2,171 LOC; omni_shape_b_openapi.rs identified as ~40% of class
- Audit implication: per-file promote-or-carve discipline applies
- Per-PR review state-space framing (Director conformance read flags
  absent dissolution-path mapping)
- Re-audit cadence note (this is window-relative intro composition,
  not full main §3.8 audit; per feedback_intro_rate_not_residual_share)

Citations grep-verified at HEAD eed86ff: all 9 NON_TEST files exist
with stated LOC; FRAGMENTS entry confirmed in sg0_census_test.rs:688-691.

* docs(briefs): Director scaffold-fill for Cluster M Phase 3 reflected-Dag + DimensionReport bulk-port worker briefs

Per feedback_pre_authored_brief_queue + feedback_director_mgr_energy_input
(Director energy INTO system until real workflow substrate exists).

Verification Mgr (clever-tern-670) status pass (msg_755c3f43) identified
Phase 3 dissolution-rate bottleneck as Mgr-tier brief-authoring bandwidth
on the two biggest unauthored classes:

- Reflected-Dag structural assertion family (~25-30 entries; 16 seed-named)
- Generic DimensionReport / runner-discipline family (~20-25 entries; 10 seed-named)

These ~50 entries combined are roughly half of the #84 EXPECTED_HAND_AUTHORED_TEST
partition (116 entries on origin/main eed86ff). Authoring scaffolds + Mgr
finalization + dispatch should land bulk-port PRs within 7-10 days, with
velocity-tripwire arrow (12.7:1 intros:dissolves at gunbc#846 c#4425420798)
flipping intra-week.

Authority split per Director msg_eb2372c7 to PM:
- Director: scaffold shape (this commit) — locked-design citations, substrate
  carrier references at exact lines, Phase-2 pattern site refs, hard constraints,
  STOP-and-escalate criteria, decomposition recommendations.
- Verification Mgr: finalization — complete inventory (Mgr-fill placeholders
  marked throughout), per-entry classification, pilot selection, dispatch.

Substrate citations grep-verified via Verification Mgr msg_755c3f43:
- ProgramGenerator/ProgramShape/Quantifier/QuantifiedTestClaim/SuiteClaim:
  src/v3/std/verification.dag:118-133 + :379-402 (carriers landed)
- TestSuite.claims still List<TestClaim>: verification.dag:404-407 (staged
  trigger at :394-399) — Reflected-Dag class CONSUMER-GATED on this flip
- Phase-2 pattern: t_pb_b_1_dag_runner_test.rs:257-357 (R3_GATE_87_CEMENTING_REGEN_SUITES,
  run_suite_all_pass_with_expected_claim_names)
- Receipt discipline: r3_gate_87_lens_cementing_regen_receipts_test.rs:13-24 + :122-132
- DimensionReport class NOT consumer-gated (Phase-2 pattern is the load-bearing
  predicate, not full #87 PASSING, per feedback_construction_over_ratchets)

* docs(briefs): Director scaffold-fill for R3 CI Layer 2 path-conditional gating

Per PM ratification at gunbc#828 c4425726922 + Director ratification msg_a77c7f42
(Verification Mgr routing per feedback_parallel_representation_debt coherence).

Bridge-debt with named dissolution trigger: when gate
ci_uses_provable_minimal_affected_set_selection lands, the affected-set
Introspect-lens output (canvas PR #2713) replaces the bridge's
required_paths_regex column.

Brief covers:
- §0 scope: extend PR #2718's changes job, do not parallel
- §1 mechanism: per-group skip_* boolean outputs + STEP-level if: on v3
- §2 inventory sources (slow-test-exemptions.txt + /tmp/v3-test-timings.log
  + NEW per-group required-paths mapping)
- §3 per-dimension structural target — every entry has dimension: Dimension
  field matching lens enum (parallel-representation-debt prevention)
- §4 hard constraints (8 invariants)
- §5 acceptance
- §6 decomposition (Mgr-fill recommendation: cost_lens pilot first)
- §7 STOP-and-escalate criteria
- §8 bridge-debt + dissolution path explicit

Verification Mgr (clever-tern-670) fills inventory + per-group regex +
dispatch. Director scaffold preserves coherence; Mgr finalizes per
feedback_director_mgr_energy_input.

* docs(briefs): fix Layer 2 YAML naming inconsistency (skip_cost → skip_cost_lens)

Per cursor APPROVE_WITH_COMMENTS at sha 04c5b08 (review 9701):

> The changes outputs define skip_cost, but the v3 step's if: uses
> needs.changes.outputs.skip_cost_lens. That disagrees with the same brief's
> post-dissolution sketch (skip_$group with cost_lens → skip_cost_lens, lines
> 129-134). Not a formal invariant breach by itself, but it is easy for an
> implementer to copy the wrong name and get an always-on/off step.

Fix: normalize the example YAML outputs block to match the if: lines and the
post-dissolution sketch. Naming convention: skip_<group_name> where
<group_name> matches the per-group table's group_name column verbatim
(no abbreviation). Updated all 4 example outputs:

  skip_lens   → skip_complexity_lens (was vague; tied to specific group)
  skip_emit   → skip_emit_target (matches starting template at §2)
  skip_parser → skip_parser_grammar (matches starting template)
  skip_cost   → skip_cost_lens (matches if: line + post-dissolution sketch)

Also added an inline comment documenting the naming convention so future
copy-paste from the example stays mechanically correct.

* docs(briefs): cite PM pre-staged Mgr-fill template (PR #2721) + converge pilot recommendation on Cluster B

Per PM msg_bba47649 — pre-staged Mgr-fill template landed as PR #2721
(docs/briefs/r3-ci-layer-2-pm-prestaged-mgr-fill-template.md, 220 lines).

Two scaffold updates:

1. §2 (inventory sources): replaced 'PM pre-staged skeleton to be attached
   if/when available' speculative reference with explicit cite-and-link to
   the landed template doc. Describes what the PM template provides:
   - All 78 slow-test-exemptions.txt entries grouped into 9 clusters (A-I)
   - (test_pattern, dimension, required_paths_regex) skeleton table
   - 12 [Mgr-fill] placeholders for substrate-lens / R3-V L4/L7 / R1C-E /
     free-consequences cross-target tracing

2. §6 (decomposition): converged my prior cost_lens-first pilot
   recommendation with PM's Cluster B recommendation — these are the same
   family (Lane 2 Stage 2d symbolic cost = cost-lens). Updated wording to
   reflect Cluster naming + cross-citation to PM template's Cluster B
   detail. Added [Mgr-fill] placeholder resolution wave to decomposition.

Inline sketch table retained as illustrative; defer to PM template for
actual starting inventory.

* WIP: gunbc Director

* docs(briefs): fix singular dimension → Set<Dimension> per PM caught semantic violation

PM (msg_ab551c52) surfaced codex RC on template PR #2721 (review #9707):
singular 'dimension:' field violates locked-design §2 union semantics. A
multi-dim consumer (e.g., LBP demonstration reading both complexity + cost)
declared with singular dimension: cost would be silently skipped when only
complexity changes — fail-open violation against P3.

PM fixed their template at dedcf69: dimension → dimensions (Set<Dimension>),
union-formula clarified, multi-dim rows expanded.

This brief had the same singular semantics; absorbed the fix per PM
recommendation so Verification Mgr inherits coherent dim-set semantic across
both authority chain artifacts (brief + template).

Changes:
- §0 authority bullet: contains(single) → (∩ ≠ ∅) intersection-non-empty;
  dimension: Dimension → dimensions: Set<Dimension>
- §2 table column rename + type spec + union semantics note + multi-dim
  consumer guidance
- §2 starting template citation updated to reflect post-fix template at
  dedcf69
- §3 section header renamed; substantive paragraph explaining WHY
  Set<Dimension> not Dimension (cites PM caught violation + P3 fail-open
  framing)
- §3 YAML example: jq script updated to set-intersection check
- §4.5 hard constraint: dimensions: Set<Dimension> with members from enum;
  empty set invalid
- §5 acceptance: every group has dimensions: Set<Dimension>; multi-dim
  fidelity language
- §6 pilot description: 'singleton {cost} dimensions' phrasing; class wave
  reviewer-check language updated
- §7 STOP: added multi-dim escalation path; explicit warning against
  defaulting to singleton {primary}
- §8 surviving artifact: (group_name, dimensions) — set-typed column survives
- inline illustrative table: explicit set-literal notation with multi-dim row
  example (lbp_demonstration: {complexity, cost})

Same authority chain absorbs cleanly: brief (primary) + template (data
attachment) now both set-typed; Verification Mgr inherits coherent
semantic.

* docs(briefs): fix boolean polarity inversion + add polarity invariant per openai-pro RC on template

PM (msg_9a188e22) surfaced openai-pro BLOCKING re-review (#9721) on template
PR #2721 at 93080af — caught load-bearing boolean polarity inversion:
brief stated skip_* formula as (affected ∩ row.dimensions) ≠ ∅ (skip when
intersection NON-empty) while CI consumer wires if: skip != 'true' (run
when skip is false). Net effect: literal-following Mgr/worker would wire
the gate to silently skip AFFECTED tests when intersection is non-empty.
TESTING.md + Boundary Discipline violation.

PM fixed template at 262f42d (4 sites inverted; explicit polarity table
added at §1/§3/§4/§5).

Same risk on this brief (#2719) at the post-dissolution mapping site I
authored when absorbing the prior dim-set fix at efacecd. Fix:

§0 authority bullet (line 10, the inversion site):
  before: 'skip_* flags become (∩ ≠ ∅)' [INVERTED — fail-open]
  after:  'skip_* flags become skip_<group> = (∩ = ∅)' [canonical]
  + explicit polarity check note + carrier-vs-contract explanation
  + skip-form / run-form equivalence stated

§3 substantive paragraph (after Set<Dimension> WHY): added Polarity
invariant block citing PM's caught inversion + 262f42d fix + explicit
warning that skip = (∩ ≠ ∅) is the canonical fail-open boolean-polarity
bug pattern.

§4 hard constraint #5 (dimensions field): added inline Polarity invariant
restating the canonical skip-form + run-form equivalent + 'never invert'
clause.

§5 acceptance: added 'Polarity check passes' criterion enumerating the
acceptable forms + naming the inverted form as the fail-open pattern to
reject in review. Self-test text clarified: cost-dimension groups run,
other-dimension groups skip (verifies correct polarity in actual gate).

YAML example at §3 (lines 139-149) was already polarity-correct (skip iff
intersection empty; skip=true when intersection empty) so unchanged.

Single-pass absorption per PM recommendation — both brief and template
now lockstep on polarity semantics. Verification Mgr inherits both files
without polarity mismatch in finalization.

* WIP: gunbc Director

* docs(briefs): align §0 example names with §1 naming convention (cursor exploratory)

Per cursor APPROVE exploratory observation on PR #2719 sha 13b0db9
(review #9732):

§0 line 25 illustrative outputs used abbreviated names (skip_lens /
skip_emit / skip_parser) while §1 line 53-54 establishes strict
'skip_<group_name>' naming convention matching the per-group table
verbatim. Non-policy violation per cursor but tightening avoids ambiguity
for implementer.

Fix: replace abbreviated names with full-form (skip_cost_lens /
skip_emit_target / skip_parser_grammar) + cross-reference §1 naming
convention in the same sentence. Brief now consistent across all naming
sites.

* docs(briefs): add P3 fail-closed shared-infrastructure full-run bucket per codex BLOCKING

codex REQUEST_CHANGES on PR #2719 at sha 52c6cf0 (review #9744):

Line 102 narrowed required-paths inventory to 'src/v3/*' deps only; the
illustrative table at lines 114-118 followed that shape. A PR that changes
shared test infrastructure or selection machinery outside src/v3/*
(.github/workflows/ci.yml, scripts/*, Cargo.lock, rust-toolchain.toml,
etc.) would be classified as 'unaffected' for every per-group regex and
silently skip tests whose behavior actually changed.

That's the fail-open boundary class P3 forbids + TESTING.md
behavior-driven discipline violation. Real correctness issue in the
proposed mechanism, not just an implementation detail.

Fix: add shared-infrastructure full-run fail-closed bucket as the
join-point that catches inter-group / cross-cutting changes:

§2 (inventory sources): added 'Shared-infrastructure full-run fail-closed
bucket' subsection with explicit mechanism — changes job computes
force_full_run = (any changed file matches shared-infra regex); when
true, all per-group skip_* short-circuit to false. Regex spec:
^(\.github/.*|scripts/.*|Cargo\.(toml|lock)|rust-toolchain\.toml|
\.cargo/.*|build\.rs)$. Names the structural rationale: per-group
regexes cover ONLY their own src/v3/* deps; the full-run trigger is
the join-point. Fail-closed by construction.

§4 hard constraint #9 (new): formalizes the invariant + 'never collapse
the full-run trigger into per-group regexes' (structural fail-open shape).

§5 acceptance: added 'Shared-infrastructure full-run check passes' as
separate criterion + self-test case (c) — a PR touching only
.github/workflows/ci.yml or Cargo.lock or scripts/check-test-timeout.sh
MUST run all test groups. Expanded self-test from 3 to 4 cases (a/b/c/d).

§2 added [Mgr-fill]: validate shared-infra regex against representative
recent PRs.

Single-pass absorption; brief now P3 fail-closed at the cross-cutting
boundary.

* WIP: gunbc Director

* docs(briefs): fix two openai-pro BLOCKINGs — harness-arm in shared-infra regex + cargo test substring not glob

openai-pro REQUEST_CHANGES on PR #2719 at sha 0d3b44b (review #9749 +
manual c4426188322):

BLOCKING #1 (P3 Fail-Closed): brief at line 104 names 'harness code' as
a class to catch in full-run regex but the actual regex at line 109 had
no harness/test-selection arm. Harness-only changes (e.g., to
tests/integration/common/* or sg0_census_test.rs) would miss both
full-run regex AND per-group regexes — silent skip.

BLOCKING #2 (TESTING.md fail-closed CI): test_pattern field documented
as 'cargo test arg pattern' but examples used glob-looking syntax
(cost_lens_*, *_emit_*). Cargo positional test arg is a libtest SUBSTRING
filter, not a glob. Worker following the brief literally would produce
a step that runs zero intended tests + exits successfully — silent skip
converting 'selected group tested' into 'selected group filtered out.'

Fixes:

#1 (harness arm in shared-infra regex):
- §2 mechanism: extended regex to include
  src/v3/compiler/tests/integration/common/.*,
  sg0_census_test.rs, test_runner_test.rs, t_pb_b_1_dag_runner_test.rs,
  integration.rs, integration test entry points
- §2 new paragraph naming the harness/test-selection-machinery arms
  explicitly + hard rule: harness-class files MUST never appear in a
  per-group required_paths_regex
- §4 hard constraint #9: extended invariant to include harness class
  with explicit file list
- §5 acceptance: extended self-test case (c) to include harness-class
  example (common/cached_compile.rs) + explicit verification list

#2 (cargo test substring, not glob):
- §1 YAML examples: cost_lens_* → cost_lens; *_emit_* → emit; added
  IMPORTANT comment explaining libtest substring semantics +
  forbidding glob syntax
- §2 test_pattern column spec: re-documented as 'libtest test-name
  SUBSTRING filter (NOT a glob)' with cost_lens example + glob
  forbiddance + --exact alternative
- §2 inline illustrative table: cost_lens_* → cost_lens (and others);
  added trailing comment naming substring semantics
- §4 new hard constraint #10: test_pattern is substring filter not
  glob; self-test that the value substitutes verbatim into cargo test
  and runs positive number of tests
- §5 acceptance: new 'test_pattern substring-filter check passes' criterion
  with empirical pilot-wave validation requirement

Brief now P3 fail-closed at both the boundary (shared-infra full-run
including harness) AND the selector (substring filter that workers can
copy verbatim without silent zero-test execution). Single-absorption
pass; awaiting fresh review at new HEAD.

* docs(briefs): reframe PM template citation per codex P1/P2 — template is on PR #2721, NOT yet landed on main

codex REQUEST_CHANGES on PR #2719 (review #9754):

Line 128 named docs/briefs/r3-ci-layer-2-pm-prestaged-mgr-fill-template.md
as a 'landed' starting authority, but git ls-tree origin/main returns no
blob and git ls-files returns nothing. A worker following this brief
would be sent to a non-existent source of truth — INVARIANTS P1/P2
authority-grounding violation in a dispatch document.

Verified at HEAD:
- git ls-tree origin/main -- docs/briefs/r3-ci-layer-2-pm-prestaged-mgr-fill-template.md → empty
- gh pr view 2721 → state=OPEN, mergedAt=null
- Template lives on PR #2721's branch only

Fix: reframe the template citation to acknowledge PR #2721 is open-not-landed.
- 'landed via PR #2721' → 'open as PR #2721 ... NOT yet landed on main'
- Added codex BLOCKING citation + verification receipt (git ls-tree result)
- Added explicit authority caveat: Verification Mgr finalization MUST
  coordinate merge sequencing — (a) merge #2721 first, OR (b) read from
  PR #2721 branch until it merges
- Named PM (deep-wolf-155) as PR #2721 author + cross-link for merge coordination
- Cited sha 262f42d (PR #2721 post-fix state per PM msg_125e3aa5)

Brief now accurately grounded on the actual file location (PR #2721 branch)
with merge-sequencing guidance for Mgr finalization. Authority chain
honest about in-flight vs landed state.

* WIP: gunbc Director

* docs(briefs): absorb 3 BLOCKING findings (Brian + codex) — R4 lifecycle reframe + canonical 2-step + count fix

Brian inline BLOCKING #1 + codex BLOCKING #1 (P5 dissolution-trigger
authority): brief framed dissolution as R3 close-blocking gate
'ci_uses_provable_minimal_affected_set_selection' but
docs/design-affected-set-lens.md:3 = 'R4 wishlist', :354 = 'CI integration
sketch (deferred to R4 full delivery)', :366 = 'CI integration is R4
full-delivery work'. No ROADMAP authority exists for the cited gate name
— that was Director-tier speculation.

Brian inline BLOCKING #2 + codex BLOCKING #2 (Facts Flow Forward / surviving
schema): §3 post-dissolution sketch only encoded dimension intersection,
silently dropping NodeRef intersection. Canonical 2-step per design §5:359
requires BOTH (TestClaim.refs ∩ affected_nodes) ≠ ∅ AND (TestClaim.dims ∩
changed.dims) ≠ ∅. Reducing surviving schema to (group_name, dimensions)
too early.

codex non-blocking: slow-test-exemptions.txt count cited as 78 (PM
template value); actual is 80 at 2026-05-12T00:50Z (verified locally:
grep -v '^#' ... | grep -v '^$' | wc -l = 80).

Fixes (single absorption pass):

§0 'Bridge-debt → dissolution lifecycle' bullet:
- Reframed from 'R3 close-blocking gate' to 'R4-bounded dissolution
  lifecycle (NOT R3 close)' with explicit citation of design doc :3 + :354
  + :366. Names R4.B as R4 owner. Removes the speculative gate name.
  Names Brian's BLOCKING #1 absorption.

§0 NEW 'Post-dissolution selection semantics (canonical 2-step join)'
bullet: explicit NodeRef + dimension joins per design :359; run formula;
skip formula; bridge coarseness acknowledgment (path-regex over-approximates
canonical lens; fail-closed-safe but coarser). Names Brian's BLOCKING #2
absorption.

§0 polarity check bullet: updated skip-form to reflect 2-step (NodeRef-empty
OR dim-empty ⇒ unaffected ⇒ skip).

§2 inventory source (a): count 78 → 80 at 3 sites (replace_all), with
explanation that count grows over time + Mgr re-runs grep at finalization
rather than relying on stale citations.

§2 table column spec: added 'testclaim_references' as 5th column. Cited
Brian's BLOCKING #2; explains bridge-tier proxy vs post-dissolution proxy.

§2 [Mgr-fill]: extended to require testclaim_references computation per
canonical 2-step.

§3 YAML post-dissolution sketch: rewrote classify step to compose BOTH
NodeRef AND dimension intersections via jq + cite Brian's BLOCKING #2
absorption inline. Header comment names R4.B authority and acknowledges
no current ROADMAP gate ID.

§4 #4 PR-body bridge-debt template: reworded from 'R3 close-blocking gate'
to 'R4.B Introspect-lens saturation lane CI integration delivery; NOT R3
close-blocking.'

§8 surviving artifact: corrected from (group_name, dimensions) to
(group_name, dimensions, testclaim_references) per canonical; cited
Brian's BLOCKING #2.

Removed all references to 'ci_uses_provable_minimal_affected_set_selection'
as a current ROADMAP gate name; replaced with R4.B owning-lane references
+ explicit acknowledgment of authority gap.

Brief now P5-honest: dissolution trigger is checkable (R4.B owning lane)
even if no concrete gate ID yet; surviving schema preserves both lens
join inputs per canonical algorithm.

* docs(briefs): reconcile §3 substantive + §7 STOP with §0/§8 — surviving schema is 3-column (cursor internal-consistency catch)

cursor REQUEST_CHANGES on PR #2719 sha 540113f (review #9767):

Two internal contradictions surfaced from my partial absorption of Brian's
BLOCKING #2:

(a) §3 substantive paragraph still said '(group_name, dimensions) mapping
survives the dissolution — only required_paths_regex column gets retired'
contradicting §0 + §8 which were updated to 3-column (group_name,
dimensions, testclaim_references).

(b) §7 STOP bullet referenced 'Layer 2 dissolution shape doesn't match
(group_name, dimensions) schema' — 2-column framing, same contradiction.

Fix:

§3 substantive paragraph (around the parallel-representation-debt rationale):
- 2-column → 3-column framing
- both dimensions AND testclaim_references must be authored
- cite design §:359 canonical 2-step join
- cite cursor internal-consistency catch alongside Brian's BLOCKING #2

§7 STOP escalation bullet:
- (group_name, dimensions) → (group_name, dimensions, testclaim_references)
  + cite canonical 2-step join

Verified via grep: all remaining
references are within meta-statements explicitly documenting the removal
(line 10 + line 268); no live references remain. All
appearances are either in updated 3-column contexts or in meta-statements
referencing the absorption (line 15 catch citation).

Brief now internally coherent across §0, §3, §7, §8 on:
- dissolution trigger (R4.B owning lane, NOT removed-gate-name)
- surviving schema (3 columns including testclaim_references)
- canonical 2-step join semantics

* docs(briefs): fix stale 78 inventory references at §2 lines 114 + 141 per openai-pro BLOCKING

openai-pro REQUEST_CHANGES on PR #2719 sha 8ae7938 (review #9779):

Brief had stale '78 active >2s entries' at line 114 + 'All 78 ... entries'
at line 141, despite §0 line 19 + §2 line 157 stating live count is 80
and Mgr should re-run count at finalization. A worker following §2
literally could build the gating table from stale 78-entry basis,
omitting 2 slow-test entries — fail-open shape against the brief's own
P3 fail-closed contract (under-inventory = exemption falls in neither
per-group regex nor full-run bucket = silently skipped).

Fix:

§2 inventory source (a) (line 114): replaced 'start with the 78 active
>2s entries' with 'start with the current live count of active >2s
entries (Mgr MUST re-run grep ... | wc -l at finalization; 80 at
2026-05-12T00:50Z but count grows; do NOT cite the stale 78 from PM
template PR #2721 or any earlier reference)'. Added 'fail-closed
completeness invariant' inline: every active exemption MUST appear in
either a per-group required_paths_regex OR the harness/shared-infra
full-run bucket; no exemption left unclassified.

§2 PM template description (line 141): 'All 78 entries' → 'PM-grouped
entries (PM template snapshot was 78 at template authoring time; live
count grows — Mgr re-verifies via wc -l at finalization, NOT this
stale historical reference)'. Added note that the 9-cluster taxonomy
survives count growth; Mgr maps new entries to existing clusters or
escalates if a new cluster surface emerges.

Brief is now internally consistent on inventory-count freshness:
- §0 line 19: live 80 with verification command
- §2 line 114: re-run command at finalization; explicit do-not-cite-78 instruction
- §2 line 141: PM template snapshot historical; live count grows
- §2 line 157 (Mgr-fill): re-run grep, don't trust stale citations

12th distinct review-class catch this polish cycle: inventory-citation
freshness as fail-closed completeness invariant.

* docs(briefs): §5 acceptance requires testclaim_references explicitly per codex BLOCKING #9780

codex REQUEST_CHANGES on PR #2719 sha 8ae7938 (review #9780):

Finding #1 (stale 78 at lines 114 + 141) already fixed at prior commit
487d175; codex finding overlaps with openai-pro #9779 absorbed before.

Finding #2 (new): §5 acceptance at line 228 only required dimensions:
Set<Dimension> on each group entry, NOT testclaim_references: Set<NodeRef>,
even though the brief makes that column load-bearing at:
- §0 line 104 (post-dissolution selection canonical 2-step)
- §3 line 178 (substantive paragraph: 3-column surviving schema)
- §8 line 269 (surviving artifact 3-column)

A Mgr reading §5 acceptance literally could call PR-set 'done' with
dimensions-only column population — that's the dimensions-only closeout
codex flags as facts-flow-forward violation.

Fix: §5 acceptance adds new explicit criterion:
'Every group entry has testclaim_references: Set<NodeRef> field' with
explicit citation chain (design §:359 + Brian BLOCKING #2 + codex
BLOCKING #9780). Includes bridge-tier-proxy vs post-dissolution-proxy
note. Includes 'Dimensions-only acceptance closeout is rejected: P2
facts-flow-forward requires both lens-join inputs.'

§5 acceptance now coherent with §0/§3/§8 on the 3-column surviving
schema; no path to 'done' that skips testclaim_references.

13th distinct review-class catch this polish cycle:
acceptance-vs-substantive-text divergence on load-bearing fields.

* docs(briefs): fix polarity-bullet dimensions-only residuals per cursor catch on #2725 review

cursor APPROVE_WITH_COMMENTS on PR #2725 (review #9799) but finding applies
to PR #2719's brief — lines 208 + 217 Polarity invariant bullets restated
post-dissolution skip/run formula via dimensions-only, conflicting with
the canonical 2-step join correctly stated at §3 substantive paragraph
(line 200) + §3 YAML sketch (line 178-188) + §5 acceptance (line 231-232).

Real residual from partial absorption (same class as catch #11 cursor
internal-consistency: when canonical algorithm gets corrected, polarity
bullets need parallel update).

Fix: update §3 Polarity invariant paragraph + §4 hard constraint #5
Polarity invariant sub-bullet to compose BOTH NodeRef AND dimension
intersections per canonical 2-step join:

run = (refs ∩ nodes) ≠ ∅ AND (dims ∩ dims) ≠ ∅
skip = ¬run = either intersection ∅

Explicitly names TWO fail-open bug patterns: (a) inversion (skip = (∩ ≠ ∅))
and (b) dimension-only collapse (drops NodeRef-step). Bridge-tier
over-approximation note preserved (bridge runs more tests than canonical;
fail-closed-safe direction).

14th distinct review-class catch this polish cycle: polarity-vs-canonical-
join-coupling — when canonical algorithm gets updated, polarity bullets
need parallel update to compose both intersections, not just dimensions.

* WIP: gunbc Director

* docs(briefs): fix (dims ∩ dims) typos to (dims ∩ changed_dims) per cursor #9821 + harmonize line 216 notation

cursor APPROVE_WITH_COMMENTS on #2719 review #9821: notation slip at
lines 213 + 229 — '(dims ∩ dims) = ∅' is self-intersection (always
trivially the set itself if non-empty) and doesn't match the canonical
formula '(dims ∩ changed_dims) = ∅' stated at line 211-212. Workers
copying the shorthand could encode the wrong predicate (always-empty if
changed_dims absent / never-empty if treated as identity).

Fixes:

Line 213 (canonical 2-step join boxed formula): (dims ∩ dims) → (dims ∩
changed_dims) matching the 'AND' clause at line 212.

Line 229 fail-open pattern (b) dimension-only collapse: 'skip = (dims ∩
dims) = ∅' → 'skip = (dims ∩ changed_dims) = ∅ (using ONLY the
dimension intersection clause, dropping the NodeRef-intersection step
from the canonical conjunction)'. Explanatory framing added.

Line 216 exploratory: 'skip = (affected ∩ group.dimensions) = ∅' →
'skip = (dims ∩ changed_dims) = ∅ (i.e., using ONLY the dimension
intersection clause...)'. Harmonized with §3 canonical notation
(dims/changed_dims throughout); reduced reader-friction per cursor's
exploratory observation.

20th distinct review-class catch this polish cycle:
self-intersection-notation-shorthand-vs-canonical — when shorthand
'(X ∩ X)' is used instead of the canonical '(X1 ∩ X2)' join expression,
it's notation-class fail-open (workers may copy literally and lose
the distinction between the operand sets).

* WIP: gunbc Director

* docs(briefs): remove residual fixed-count wording

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* fix(#2719): parity fix for openai-pro BLOCKING regex finding on #2725

The shared Layer 2 brief lives on both #2719 + #2725 branches; openai-pro
caught the regex hole on #2725 (root-anchored Cargo.toml/build.rs misses
crate-local manifests + build scripts). Cross-branch parity required to
avoid revert-on-merge when one branch lands first.

Applied (.*/)?Cargo\.(toml|lock) and (.*/)?build\.rs same as #2725
absorption commit. Added explanatory paragraph cross-referencing the
openai-pro finding.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Verified the relayed cursor/composer-2 artifact from review 9853 against current head 19c1010. The artifact itself says "Findings - None" and "Verdict APPROVE"; the current diff still only adds docs/briefs/r3-affected-set-introspect-lens-prototype-worker.md, and the cited IntrospectApplication live-substrate note remains present in the brief. No code or doc change is warranted for this relay; it appears to be an approving review surfaced as blocking. — sent from clever-tern-670

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 8151141a · Trigger: schedule
  • Thinking: 227s wall

Non-blocking — Strengths

  • docs/briefs/r3-affected-set-introspect-lens-prototype-worker.md Classified as design/docs; the canvas is grounded as a substrate-feasibility probe with explicit receipt and escalation gates.

ROADMAP — Verified

  • T-PB-A/T-PB-B: The brief preserves the 0-floor direction by blocking new Rust analysis, Rust tests, runner bridges, and positive SG-0 delta.

✅ No blocking concerns.

@briansrls

Copy link
Copy Markdown
Contributor Author

Verified this tests/dag runner finding against current head 19c1010. It is already addressed in the brief: §1 item 7 states tests/dag is not self-discovering and requires naming an existing TestRunner/suite path or STOP; §4 item 7 forbids a new Rust runner bridge; §5 requires a zero-SG-0 executable receipt with command/result; §6 stops if fixtures cannot execute through an existing runner path. No further code/doc change is warranted for this relay. — sent from clever-tern-670

@briansrls

Copy link
Copy Markdown
Contributor Author

Verified the relayed Codex review posted at 2026-05-12T03:08:33Z. It says "No blocking concerns" and classifies the current canvas direction as preserving the 0-floor direction, blocking new Rust analysis/tests/runner bridges, and requiring substrate-feasibility receipts. Current head 19c1010 is green and still contains the runner-coverage fix in §1/§4/§5/§6. No code or doc change is warranted for this feedback item. — sent from clever-tern-670

briansrls added a commit that referenced this pull request May 12, 2026
* docs(audit): R3 deferral anti-pattern audit (PROPOSAL — Director-authored)

Surfaces the broader anti-pattern class around cost-lens Miss dissolution
(operator-ratified 2026-05-11). Grep-verified ~1600+ instances of
deferral-via-wrapper-variant in v3 compiler production surface across 13
categories (Option<T>, panic!, .expect(), NotYetImplemented, DescentUnknown,
ArrowBody::Pending, _ => catch-alls, etc.).

Per operator-directive: "Miss should go away entirely; if something in
substrate defines a Miss it should fail and be investigated asap" — extended
to whole anti-pattern class. Each category dissolution path proposed.

Tagged for PM (deep-wolf-155) + Mgr ratification: scope, sequencing, PR-template
ratchet authoring authority.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(audit): address openai-pro REQUEST_CHANGES — narrow Miss-class scope; reconcile DescentUnknown authority

Per openai-pro review (#2708 c#4425020297, verdict REQUEST_CHANGES):

3 valid blocking findings addressed:

1. LAYER MODEL — §3.2 DescentEvidence::DescentUnknown removal conflated
   Miss-class deferral with fail-closed lattice bottom (INVARIANTS.md:63-66).
   Reframed: dissolution requires PM-tier ratification on (a) keep 3-variant
   lattice + construction-side narrowing OR (b) authority update first +
   2-variant collapse. No worker dispatch until PM ratifies.

2. INVARIANTS + modeling-discipline — §1 row 1, §2.2 paragraph: "all 83
   Option<T> = pure deferral" overgeneralized. Per modeling-discipline.md:41-50
   + CODING.md:95-97, Option<T> is allowed when absence is meaningful.
   Reframed as triage candidates with per-site classification (error-None
   = Miss-class; legitimate-absence = compliant); explicit "don't bulk-convert."

3. CODING.md — §4 review checklist phrased as "flag for conversion" which
   conflicts with CODING.md:307-309 (Option/Result OK when meaningful).
   Reframed as "flag for justification": reviewer asks, author justifies;
   non-compliant cases convert, compliant wrappers survive.

§0 framing also clarified: Miss-class deferral ≠ all Option<T>; per-site
classification required; bulk-conversion would itself be a discipline violation.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address codex REQUEST_CHANGES — eliminate internal authority contradictions

Per codex review (#2708 c#4425182*, verdict REQUEST_CHANGES):

2 valid blocking findings addressed:

1. §1 table — rows 2-7 stated definitive violations ("should be typed
   Diagnostics", "admits non-exhaustiveness", "explicit 'I haven't decided
   this'") while §2.2 later correctly narrowed these to per-site triage.
   Two conflicting authorities within the same brief violated INVARIANTS P2
   single-authority discipline. Fix: table notes now reflect the triage
   framing (boundary tooling vs interior substrate flow per CODING.md
   307-309; closed-enum vs deliberate-default catch-alls; etc.). Rows 9-13
   tagged with explicit cross-references to §3 disposition.

2. §5 sequencing — proposed §3.2 (DescentUnknown) same-batch dispatch with
   §3.1, but §3.2 itself blocked dispatch on PM ratification of path (a)
   vs (b). Fix: §5 now explicitly marks §3.2 + §3.6 as PM-blocked authority
   gates; only path (a) ratification would enable same-batch with §3.1;
   path (b) requires INVARIANTS.md edit landing first. Authority-gate
   summary appended.

Also relabeled §2.1 "Pure deferral" → "Miss-class deferral" and removed
DescentUnknown from the auto-classified list (consistent with §3.2 gate).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address inline blocking — reconcile §3.3 DescentResidual with Director-ratified γ-shape

Per inline review finding at docs/audit/r3-deferral-anti-pattern-audit-2026-05-11.md:101
(2026-05-11T21:03:41Z):

> "BLOCKING: §3.3 reclassifies the Director-ratified terminal DescentResidual
> as Miss-shape without reconciling the current termination.dag authority,
> which violates P1 modeling faithfulness and locked-decision discipline."

Valid finding. The `DescentResidual = EvidenceUnknown(NonStrictEvidence) |
EvidenceIncomplete` shape was Director-ratified via the
illegal-states-unrepresentable rationale in
docs/briefs/r3-substrate-descent-execution-proof-worker.md (gunbc#828
issuecomment-4395060514). The audit incorrectly conflated the analyzer's
runtime-failure surface with a Miss-class design-laziness deferral.

Same pattern as the prior §3.2 DescentUnknown correction (openai-pro
REQUEST_CHANGES):

- §3.3 reframed: no direct dissolution proposed; instead, pre-dispatch
  requirement to read existing authority + produce grep-verified reason
  + PM ratification.
- §1 table row 11: tagged "authority-conflicting per Director-ratified
  γ-shape — compliant as written today."
- §2.1: removed residual from Miss-class auto-classified list; appended
  to the "NOT auto-classified" entries alongside DescentUnknown.
- §5 sequencing: §3.3 now authority-blocked (same as §3.2 + §3.6); cannot
  same-batch with §3.1 until reconciliation lands. Authority-gate footer
  updated.

Pattern: every authority-conflicting dissolution proposal must (a) start
from grep-verified read of existing authority, (b) name the specific
authority doc affected, (c) require PM ratification before dispatch.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address inline blocking — §3.6 ArrowBody location was factually wrong

Per inline review finding at docs/audit/r3-deferral-anti-pattern-audit-2026-05-11.md:120
(2026-05-11T21:03:41Z):

> "BLOCKING: ArrowBody::Pending is stored on TypeConnective::Arrow.body/
> ResolvedArrow, not Behavior::Transform.body, so §3.6 aims the redesign
> at the wrong substrate boundary under P2 facts-flow-forward."

Verified at HEAD:
- ArrowBody enum at src/v3/compiler/src/dag.rs:1092
- Used in TypeConnective::Arrow { body, .. } patterns (bootstrap.rs:288 etc.)
- All ArrowBody::Unparsed sites in bootstrap_generated.rs are inside
  TypeConnective::Arrow { body: ArrowBody::Unparsed(...), .. }

Original §3.6 claim that ArrowBody is on Behavior::Transform.body was wrong.
Actual location is declaration-tier type-connective (Declaration.connective
= TypeConnective::Arrow { body: ArrowBody::Pending }).

Fix: §3.6 reframed. The substrate-shape question is at the declaration-tier
type-connective layer, NOT Behavior::Transform. The "paper-over" cost is at
the type-connective-walking layer; Behavior walkers already see only resolved
bodies. Revised proposal: PM ratification on R3-load-bearing-ness + Substrate
Mgr canvas on partition-vs-sum-with-Pending design question, citing
M1_DESIGN.md authority + per-walker impact analysis.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address inline blocking — LensSurfacePending is terminal, not in-progress

Per inline review finding at docs/audit/r3-deferral-anti-pattern-audit-2026-05-11.md:37
(2026-05-11T21:03:41Z):

> "BLOCKING: LensSurfacePending is a terminal ParallelismUnsupportedKind in
> the effects substrate, not an in-progress substrate state, so grouping it
> with ArrowBody::Pending needs explicit authority reconciliation before
> dispatch under P1 modeling faithfulness."

Verified at HEAD: src/v3/compiler/src/dag/effects.rs:197 places
LensSurfacePending as a variant of ParallelismUnsupportedKind, explicitly
marked 🟢 TERMINAL in code comments. It's an explicit unsupported-reason
payload for the parallelism lens, NOT a transitional in-progress state.
The "Pending" suffix is misleading.

Fix: removed LensSurfacePending from §3.6 (which only covers true pre-lowering
transitional state ArrowBody::Pending). Updated §1 table row 12 + §2.1
Miss-class list to explicitly NOT auto-classify it. Removed scope contradiction.

Pattern continues from prior corrections: every classification in the audit
needs grep-verified factual grounding. Misleading variant names ("Pending"
suffix on terminal carriers) are themselves a discipline gap.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address cursor NON-BLOCKING table nits — rows #10/#11 misattributed conflict

Per cursor APPROVE_WITH_COMMENTS review at sha 0c07f7a (2026-05-11T21:08:35Z):

> Row 10/11 phrase 'Authority-conflicting per X' but the cited authority X is
> exactly where the standing design is *defined*. The real tension is between
> the operator's Miss-elimination directive and that existing authority text,
> not 'conflict' within or stated by those authorities themselves.

Fix: reframe rows #10/#11 to name the standing authority + locate the tension
correctly:
- Row 10 (DescentUnknown): standing authority is INVARIANTS.md fail-closed
  bottom; tension is with operator directive (not within the invariant).
- Row 11 (DescentResidual): standing authority is Director-ratified γ-shape;
  carrier is compliant; my prior audit framing was the conflict, corrected in
  §3.3.

NON-BLOCKING per reviewer but legitimate clarity improvement; reviewer's verdict
was APPROVE_WITH_COMMENTS.

* docs(audit): tighten CODING.md citations — boundary roles at :311-321, not :307-309

Per cursor APPROVE_WITH_COMMENTS finding at sha 0af402f (2026-05-11T21:24:39Z):

> The notes point boundary-tooling legitimacy at CODING.md:307-309, but those
> lines only state the narrow 'Hidden panic surface' rule (library avoids
> contract-violation panics/unwrap()). The explicit Bootstrap and
> Code-generation binaries edge roles appear under 'When impurity is
> acceptable' beginning around CODING.md:311 (table ~317-321).

Fix: split the citation so:
- CODING.md:307-309 covers the contract-violation-in-library rule (interior
  substrate-flow panics dissolve to typed Diagnostic per C-8).
- CODING.md:311-321 covers the boundary roles legitimacy (Build script /
  Code-generation binaries / Bootstrap entries in the impurity-acceptable
  table).

Updated table rows #2/#3 (lines 27-28), §2.2 prose (line 66), and §4 review
checklist (line 171). NON-BLOCKING per reviewer; landing as documentation
hygiene.

* docs(audit): add §3.8.1 concrete 10-entry NON_TEST inventory per velocity-walk

Per PM ratification (msg_45457c77 in response to Director ask msg_048fdfa6):
empirical-grounding-strengthens-the-case path. §3.8 currently treats
structural_coverage_gap audit as abstract pattern; with zesty-boar-261's
velocity-walk diagnostic (gunbc#846 c#4425420798) producing a 9 NON_TEST +
1 FRAGMENTS enumerated inventory over the 7d window pre-2026-05-11, §3.8
graduates from speculative to grounded.

Adds §3.8.1 with:
- 10-entry table: file path + LOC + adjacent-lane/dissolution-path mapping
- Total 2,171 LOC; omni_shape_b_openapi.rs identified as ~40% of class
- Audit implication: per-file promote-or-carve discipline applies
- Per-PR review state-space framing (Director conformance read flags
  absent dissolution-path mapping)
- Re-audit cadence note (this is window-relative intro composition,
  not full main §3.8 audit; per feedback_intro_rate_not_residual_share)

Citations grep-verified at HEAD eed86ff: all 9 NON_TEST files exist
with stated LOC; FRAGMENTS entry confirmed in sg0_census_test.rs:688-691.

* docs(briefs): Director scaffold-fill for Cluster M Phase 3 reflected-Dag + DimensionReport bulk-port worker briefs

Per feedback_pre_authored_brief_queue + feedback_director_mgr_energy_input
(Director energy INTO system until real workflow substrate exists).

Verification Mgr (clever-tern-670) status pass (msg_755c3f43) identified
Phase 3 dissolution-rate bottleneck as Mgr-tier brief-authoring bandwidth
on the two biggest unauthored classes:

- Reflected-Dag structural assertion family (~25-30 entries; 16 seed-named)
- Generic DimensionReport / runner-discipline family (~20-25 entries; 10 seed-named)

These ~50 entries combined are roughly half of the #84 EXPECTED_HAND_AUTHORED_TEST
partition (116 entries on origin/main eed86ff). Authoring scaffolds + Mgr
finalization + dispatch should land bulk-port PRs within 7-10 days, with
velocity-tripwire arrow (12.7:1 intros:dissolves at gunbc#846 c#4425420798)
flipping intra-week.

Authority split per Director msg_eb2372c7 to PM:
- Director: scaffold shape (this commit) — locked-design citations, substrate
  carrier references at exact lines, Phase-2 pattern site refs, hard constraints,
  STOP-and-escalate criteria, decomposition recommendations.
- Verification Mgr: finalization — complete inventory (Mgr-fill placeholders
  marked throughout), per-entry classification, pilot selection, dispatch.

Substrate citations grep-verified via Verification Mgr msg_755c3f43:
- ProgramGenerator/ProgramShape/Quantifier/QuantifiedTestClaim/SuiteClaim:
  src/v3/std/verification.dag:118-133 + :379-402 (carriers landed)
- TestSuite.claims still List<TestClaim>: verification.dag:404-407 (staged
  trigger at :394-399) — Reflected-Dag class CONSUMER-GATED on this flip
- Phase-2 pattern: t_pb_b_1_dag_runner_test.rs:257-357 (R3_GATE_87_CEMENTING_REGEN_SUITES,
  run_suite_all_pass_with_expected_claim_names)
- Receipt discipline: r3_gate_87_lens_cementing_regen_receipts_test.rs:13-24 + :122-132
- DimensionReport class NOT consumer-gated (Phase-2 pattern is the load-bearing
  predicate, not full #87 PASSING, per feedback_construction_over_ratchets)

* docs(briefs): Director scaffold-fill for R3 CI Layer 2 path-conditional gating

Per PM ratification at gunbc#828 c4425726922 + Director ratification msg_a77c7f42
(Verification Mgr routing per feedback_parallel_representation_debt coherence).

Bridge-debt with named dissolution trigger: when gate
ci_uses_provable_minimal_affected_set_selection lands, the affected-set
Introspect-lens output (canvas PR #2713) replaces the bridge's
required_paths_regex column.

Brief covers:
- §0 scope: extend PR #2718's changes job, do not parallel
- §1 mechanism: per-group skip_* boolean outputs + STEP-level if: on v3
- §2 inventory sources (slow-test-exemptions.txt + /tmp/v3-test-timings.log
  + NEW per-group required-paths mapping)
- §3 per-dimension structural target — every entry has dimension: Dimension
  field matching lens enum (parallel-representation-debt prevention)
- §4 hard constraints (8 invariants)
- §5 acceptance
- §6 decomposition (Mgr-fill recommendation: cost_lens pilot first)
- §7 STOP-and-escalate criteria
- §8 bridge-debt + dissolution path explicit

Verification Mgr (clever-tern-670) fills inventory + per-group regex +
dispatch. Director scaffold preserves coherence; Mgr finalizes per
feedback_director_mgr_energy_input.

* docs(briefs): fix Layer 2 YAML naming inconsistency (skip_cost → skip_cost_lens)

Per cursor APPROVE_WITH_COMMENTS at sha 04c5b08 (review 9701):

> The changes outputs define skip_cost, but the v3 step's if: uses
> needs.changes.outputs.skip_cost_lens. That disagrees with the same brief's
> post-dissolution sketch (skip_$group with cost_lens → skip_cost_lens, lines
> 129-134). Not a formal invariant breach by itself, but it is easy for an
> implementer to copy the wrong name and get an always-on/off step.

Fix: normalize the example YAML outputs block to match the if: lines and the
post-dissolution sketch. Naming convention: skip_<group_name> where
<group_name> matches the per-group table's group_name column verbatim
(no abbreviation). Updated all 4 example outputs:

  skip_lens   → skip_complexity_lens (was vague; tied to specific group)
  skip_emit   → skip_emit_target (matches starting template at §2)
  skip_parser → skip_parser_grammar (matches starting template)
  skip_cost   → skip_cost_lens (matches if: line + post-dissolution sketch)

Also added an inline comment documenting the naming convention so future
copy-paste from the example stays mechanically correct.

* docs(briefs): cite PM pre-staged Mgr-fill template (PR #2721) + converge pilot recommendation on Cluster B

Per PM msg_bba47649 — pre-staged Mgr-fill template landed as PR #2721
(docs/briefs/r3-ci-layer-2-pm-prestaged-mgr-fill-template.md, 220 lines).

Two scaffold updates:

1. §2 (inventory sources): replaced 'PM pre-staged skeleton to be attached
   if/when available' speculative reference with explicit cite-and-link to
   the landed template doc. Describes what the PM template provides:
   - All 78 slow-test-exemptions.txt entries grouped into 9 clusters (A-I)
   - (test_pattern, dimension, required_paths_regex) skeleton table
   - 12 [Mgr-fill] placeholders for substrate-lens / R3-V L4/L7 / R1C-E /
     free-consequences cross-target tracing

2. §6 (decomposition): converged my prior cost_lens-first pilot
   recommendation with PM's Cluster B recommendation — these are the same
   family (Lane 2 Stage 2d symbolic cost = cost-lens). Updated wording to
   reflect Cluster naming + cross-citation to PM template's Cluster B
   detail. Added [Mgr-fill] placeholder resolution wave to decomposition.

Inline sketch table retained as illustrative; defer to PM template for
actual starting inventory.

* WIP: gunbc Director

* docs(briefs): fix singular dimension → Set<Dimension> per PM caught semantic violation

PM (msg_ab551c52) surfaced codex RC on template PR #2721 (review #9707):
singular 'dimension:' field violates locked-design §2 union semantics. A
multi-dim consumer (e.g., LBP demonstration reading both complexity + cost)
declared with singular dimension: cost would be silently skipped when only
complexity changes — fail-open violation against P3.

PM fixed their template at dedcf69: dimension → dimensions (Set<Dimension>),
union-formula clarified, multi-dim rows expanded.

This brief had the same singular semantics; absorbed the fix per PM
recommendation so Verification Mgr inherits coherent dim-set semantic across
both authority chain artifacts (brief + template).

Changes:
- §0 authority bullet: contains(single) → (∩ ≠ ∅) intersection-non-empty;
  dimension: Dimension → dimensions: Set<Dimension>
- §2 table column rename + type spec + union semantics note + multi-dim
  consumer guidance
- §2 starting template citation updated to reflect post-fix template at
  dedcf69
- §3 section header renamed; substantive paragraph explaining WHY
  Set<Dimension> not Dimension (cites PM caught violation + P3 fail-open
  framing)
- §3 YAML example: jq script updated to set-intersection check
- §4.5 hard constraint: dimensions: Set<Dimension> with members from enum;
  empty set invalid
- §5 acceptance: every group has dimensions: Set<Dimension>; multi-dim
  fidelity language
- §6 pilot description: 'singleton {cost} dimensions' phrasing; class wave
  reviewer-check language updated
- §7 STOP: added multi-dim escalation path; explicit warning against
  defaulting to singleton {primary}
- §8 surviving artifact: (group_name, dimensions) — set-typed column survives
- inline illustrative table: explicit set-literal notation with multi-dim row
  example (lbp_demonstration: {complexity, cost})

Same authority chain absorbs cleanly: brief (primary) + template (data
attachment) now both set-typed; Verification Mgr inherits coherent
semantic.

* docs(briefs): fix boolean polarity inversion + add polarity invariant per openai-pro RC on template

PM (msg_9a188e22) surfaced openai-pro BLOCKING re-review (#9721) on template
PR #2721 at 93080af — caught load-bearing boolean polarity inversion:
brief stated skip_* formula as (affected ∩ row.dimensions) ≠ ∅ (skip when
intersection NON-empty) while CI consumer wires if: skip != 'true' (run
when skip is false). Net effect: literal-following Mgr/worker would wire
the gate to silently skip AFFECTED tests when intersection is non-empty.
TESTING.md + Boundary Discipline violation.

PM fixed template at 262f42d (4 sites inverted; explicit polarity table
added at §1/§3/§4/§5).

Same risk on this brief (#2719) at the post-dissolution mapping site I
authored when absorbing the prior dim-set fix at efacecd. Fix:

§0 authority bullet (line 10, the inversion site):
  before: 'skip_* flags become (∩ ≠ ∅)' [INVERTED — fail-open]
  after:  'skip_* flags become skip_<group> = (∩ = ∅)' [canonical]
  + explicit polarity check note + carrier-vs-contract explanation
  + skip-form / run-form equivalence stated

§3 substantive paragraph (after Set<Dimension> WHY): added Polarity
invariant block citing PM's caught inversion + 262f42d fix + explicit
warning that skip = (∩ ≠ ∅) is the canonical fail-open boolean-polarity
bug pattern.

§4 hard constraint #5 (dimensions field): added inline Polarity invariant
restating the canonical skip-form + run-form equivalent + 'never invert'
clause.

§5 acceptance: added 'Polarity check passes' criterion enumerating the
acceptable forms + naming the inverted form as the fail-open pattern to
reject in review. Self-test text clarified: cost-dimension groups run,
other-dimension groups skip (verifies correct polarity in actual gate).

YAML example at §3 (lines 139-149) was already polarity-correct (skip iff
intersection empty; skip=true when intersection empty) so unchanged.

Single-pass absorption per PM recommendation — both brief and template
now lockstep on polarity semantics. Verification Mgr inherits both files
without polarity mismatch in finalization.

* WIP: gunbc Director

* docs(briefs): align §0 example names with §1 naming convention (cursor exploratory)

Per cursor APPROVE exploratory observation on PR #2719 sha 13b0db9
(review #9732):

§0 line 25 illustrative outputs used abbreviated names (skip_lens /
skip_emit / skip_parser) while §1 line 53-54 establishes strict
'skip_<group_name>' naming convention matching the per-group table
verbatim. Non-policy violation per cursor but tightening avoids ambiguity
for implementer.

Fix: replace abbreviated names with full-form (skip_cost_lens /
skip_emit_target / skip_parser_grammar) + cross-reference §1 naming
convention in the same sentence. Brief now consistent across all naming
sites.

* docs(briefs): add P3 fail-closed shared-infrastructure full-run bucket per codex BLOCKING

codex REQUEST_CHANGES on PR #2719 at sha 52c6cf0 (review #9744):

Line 102 narrowed required-paths inventory to 'src/v3/*' deps only; the
illustrative table at lines 114-118 followed that shape. A PR that changes
shared test infrastructure or selection machinery outside src/v3/*
(.github/workflows/ci.yml, scripts/*, Cargo.lock, rust-toolchain.toml,
etc.) would be classified as 'unaffected' for every per-group regex and
silently skip tests whose behavior actually changed.

That's the fail-open boundary class P3 forbids + TESTING.md
behavior-driven discipline violation. Real correctness issue in the
proposed mechanism, not just an implementation detail.

Fix: add shared-infrastructure full-run fail-closed bucket as the
join-point that catches inter-group / cross-cutting changes:

§2 (inventory sources): added 'Shared-infrastructure full-run fail-closed
bucket' subsection with explicit mechanism — changes job computes
force_full_run = (any changed file matches shared-infra regex); when
true, all per-group skip_* short-circuit to false. Regex spec:
^(\.github/.*|scripts/.*|Cargo\.(toml|lock)|rust-toolchain\.toml|
\.cargo/.*|build\.rs)$. Names the structural rationale: per-group
regexes cover ONLY their own src/v3/* deps; the full-run trigger is
the join-point. Fail-closed by construction.

§4 hard constraint #9 (new): formalizes the invariant + 'never collapse
the full-run trigger into per-group regexes' (structural fail-open shape).

§5 acceptance: added 'Shared-infrastructure full-run check passes' as
separate criterion + self-test case (c) — a PR touching only
.github/workflows/ci.yml or Cargo.lock or scripts/check-test-timeout.sh
MUST run all test groups. Expanded self-test from 3 to 4 cases (a/b/c/d).

§2 added [Mgr-fill]: validate shared-infra regex against representative
recent PRs.

Single-pass absorption; brief now P3 fail-closed at the cross-cutting
boundary.

* WIP: gunbc Director

* docs(briefs): fix two openai-pro BLOCKINGs — harness-arm in shared-infra regex + cargo test substring not glob

openai-pro REQUEST_CHANGES on PR #2719 at sha 0d3b44b (review #9749 +
manual c4426188322):

BLOCKING #1 (P3 Fail-Closed): brief at line 104 names 'harness code' as
a class to catch in full-run regex but the actual regex at line 109 had
no harness/test-selection arm. Harness-only changes (e.g., to
tests/integration/common/* or sg0_census_test.rs) would miss both
full-run regex AND per-group regexes — silent skip.

BLOCKING #2 (TESTING.md fail-closed CI): test_pattern field documented
as 'cargo test arg pattern' but examples used glob-looking syntax
(cost_lens_*, *_emit_*). Cargo positional test arg is a libtest SUBSTRING
filter, not a glob. Worker following the brief literally would produce
a step that runs zero intended tests + exits successfully — silent skip
converting 'selected group tested' into 'selected group filtered out.'

Fixes:

#1 (harness arm in shared-infra regex):
- §2 mechanism: extended regex to include
  src/v3/compiler/tests/integration/common/.*,
  sg0_census_test.rs, test_runner_test.rs, t_pb_b_1_dag_runner_test.rs,
  integration.rs, integration test entry points
- §2 new paragraph naming the harness/test-selection-machinery arms
  explicitly + hard rule: harness-class files MUST never appear in a
  per-group required_paths_regex
- §4 hard constraint #9: extended invariant to include harness class
  with explicit file list
- §5 acceptance: extended self-test case (c) to include harness-class
  example (common/cached_compile.rs) + explicit verification list

#2 (cargo test substring, not glob):
- §1 YAML examples: cost_lens_* → cost_lens; *_emit_* → emit; added
  IMPORTANT comment explaining libtest substring semantics +
  forbidding glob syntax
- §2 test_pattern column spec: re-documented as 'libtest test-name
  SUBSTRING filter (NOT a glob)' with cost_lens example + glob
  forbiddance + --exact alternative
- §2 inline illustrative table: cost_lens_* → cost_lens (and others);
  added trailing comment naming substring semantics
- §4 new hard constraint #10: test_pattern is substring filter not
  glob; self-test that the value substitutes verbatim into cargo test
  and runs positive number of tests
- §5 acceptance: new 'test_pattern substring-filter check passes' criterion
  with empirical pilot-wave validation requirement

Brief now P3 fail-closed at both the boundary (shared-infra full-run
including harness) AND the selector (substring filter that workers can
copy verbatim without silent zero-test execution). Single-absorption
pass; awaiting fresh review at new HEAD.

* docs(briefs): reframe PM template citation per codex P1/P2 — template is on PR #2721, NOT yet landed on main

codex REQUEST_CHANGES on PR #2719 (review #9754):

Line 128 named docs/briefs/r3-ci-layer-2-pm-prestaged-mgr-fill-template.md
as a 'landed' starting authority, but git ls-tree origin/main returns no
blob and git ls-files returns nothing. A worker following this brief
would be sent to a non-existent source of truth — INVARIANTS P1/P2
authority-grounding violation in a dispatch document.

Verified at HEAD:
- git ls-tree origin/main -- docs/briefs/r3-ci-layer-2-pm-prestaged-mgr-fill-template.md → empty
- gh pr view 2721 → state=OPEN, mergedAt=null
- Template lives on PR #2721's branch only

Fix: reframe the template citation to acknowledge PR #2721 is open-not-landed.
- 'landed via PR #2721' → 'open as PR #2721 ... NOT yet landed on main'
- Added codex BLOCKING citation + verification receipt (git ls-tree result)
- Added explicit authority caveat: Verification Mgr finalization MUST
  coordinate merge sequencing — (a) merge #2721 first, OR (b) read from
  PR #2721 branch until it merges
- Named PM (deep-wolf-155) as PR #2721 author + cross-link for merge coordination
- Cited sha 262f42d (PR #2721 post-fix state per PM msg_125e3aa5)

Brief now accurately grounded on the actual file location (PR #2721 branch)
with merge-sequencing guidance for Mgr finalization. Authority chain
honest about in-flight vs landed state.

* WIP: gunbc Director

* docs(briefs): absorb 3 BLOCKING findings (Brian + codex) — R4 lifecycle reframe + canonical 2-step + count fix

Brian inline BLOCKING #1 + codex BLOCKING #1 (P5 dissolution-trigger
authority): brief framed dissolution as R3 close-blocking gate
'ci_uses_provable_minimal_affected_set_selection' but
docs/design-affected-set-lens.md:3 = 'R4 wishlist', :354 = 'CI integration
sketch (deferred to R4 full delivery)', :366 = 'CI integration is R4
full-delivery work'. No ROADMAP authority exists for the cited gate name
— that was Director-tier speculation.

Brian inline BLOCKING #2 + codex BLOCKING #2 (Facts Flow Forward / surviving
schema): §3 post-dissolution sketch only encoded dimension intersection,
silently dropping NodeRef intersection. Canonical 2-step per design §5:359
requires BOTH (TestClaim.refs ∩ affected_nodes) ≠ ∅ AND (TestClaim.dims ∩
changed.dims) ≠ ∅. Reducing surviving schema to (group_name, dimensions)
too early.

codex non-blocking: slow-test-exemptions.txt count cited as 78 (PM
template value); actual is 80 at 2026-05-12T00:50Z (verified locally:
grep -v '^#' ... | grep -v '^$' | wc -l = 80).

Fixes (single absorption pass):

§0 'Bridge-debt → dissolution lifecycle' bullet:
- Reframed from 'R3 close-blocking gate' to 'R4-bounded dissolution
  lifecycle (NOT R3 close)' with explicit citation of design doc :3 + :354
  + :366. Names R4.B as R4 owner. Removes the speculative gate name.
  Names Brian's BLOCKING #1 absorption.

§0 NEW 'Post-dissolution selection semantics (canonical 2-step join)'
bullet: explicit NodeRef + dimension joins per design :359; run formula;
skip formula; bridge coarseness acknowledgment (path-regex over-approximates
canonical lens; fail-closed-safe but coarser). Names Brian's BLOCKING #2
absorption.

§0 polarity check bullet: updated skip-form to reflect 2-step (NodeRef-empty
OR dim-empty ⇒ unaffected ⇒ skip).

§2 inventory source (a): count 78 → 80 at 3 sites (replace_all), with
explanation that count grows over time + Mgr re-runs grep at finalization
rather than relying on stale citations.

§2 table column spec: added 'testclaim_references' as 5th column. Cited
Brian's BLOCKING #2; explains bridge-tier proxy vs post-dissolution proxy.

§2 [Mgr-fill]: extended to require testclaim_references computation per
canonical 2-step.

§3 YAML post-dissolution sketch: rewrote classify step to compose BOTH
NodeRef AND dimension intersections via jq + cite Brian's BLOCKING #2
absorption inline. Header comment names R4.B authority and acknowledges
no current ROADMAP gate ID.

§4 #4 PR-body bridge-debt template: reworded from 'R3 close-blocking gate'
to 'R4.B Introspect-lens saturation lane CI integration delivery; NOT R3
close-blocking.'

§8 surviving artifact: corrected from (group_name, dimensions) to
(group_name, dimensions, testclaim_references) per canonical; cited
Brian's BLOCKING #2.

Removed all references to 'ci_uses_provable_minimal_affected_set_selection'
as a current ROADMAP gate name; replaced with R4.B owning-lane references
+ explicit acknowledgment of authority gap.

Brief now P5-honest: dissolution trigger is checkable (R4.B owning lane)
even if no concrete gate ID yet; surviving schema preserves both lens
join inputs per canonical algorithm.

* docs(briefs): reconcile §3 substantive + §7 STOP with §0/§8 — surviving schema is 3-column (cursor internal-consistency catch)

cursor REQUEST_CHANGES on PR #2719 sha 540113f (review #9767):

Two internal contradictions surfaced from my partial absorption of Brian's
BLOCKING #2:

(a) §3 substantive paragraph still said '(group_name, dimensions) mapping
survives the dissolution — only required_paths_regex column gets retired'
contradicting §0 + §8 which were updated to 3-column (group_name,
dimensions, testclaim_references).

(b) §7 STOP bullet referenced 'Layer 2 dissolution shape doesn't match
(group_name, dimensions) schema' — 2-column framing, same contradiction.

Fix:

§3 substantive paragraph (around the parallel-representation-debt rationale):
- 2-column → 3-column framing
- both dimensions AND testclaim_references must be authored
- cite design §:359 canonical 2-step join
- cite cursor internal-consistency catch alongside Brian's BLOCKING #2

§7 STOP escalation bullet:
- (group_name, dimensions) → (group_name, dimensions, testclaim_references)
  + cite canonical 2-step join

Verified via grep: all remaining
references are within meta-statements explicitly documenting the removal
(line 10 + line 268); no live references remain. All
appearances are either in updated 3-column contexts or in meta-statements
referencing the absorption (line 15 catch citation).

Brief now internally coherent across §0, §3, §7, §8 on:
- dissolution trigger (R4.B owning lane, NOT removed-gate-name)
- surviving schema (3 columns including testclaim_references)
- canonical 2-step join semantics

* docs(briefs): fix stale 78 inventory references at §2 lines 114 + 141 per openai-pro BLOCKING

openai-pro REQUEST_CHANGES on PR #2719 sha 8ae7938 (review #9779):

Brief had stale '78 active >2s entries' at line 114 + 'All 78 ... entries'
at line 141, despite §0 line 19 + §2 line 157 stating live count is 80
and Mgr should re-run count at finalization. A worker following §2
literally could build the gating table from stale 78-entry basis,
omitting 2 slow-test entries — fail-open shape against the brief's own
P3 fail-closed contract (under-inventory = exemption falls in neither
per-group regex nor full-run bucket = silently skipped).

Fix:

§2 inventory source (a) (line 114): replaced 'start with the 78 active
>2s entries' with 'start with the current live count of active >2s
entries (Mgr MUST re-run grep ... | wc -l at finalization; 80 at
2026-05-12T00:50Z but count grows; do NOT cite the stale 78 from PM
template PR #2721 or any earlier reference)'. Added 'fail-closed
completeness invariant' inline: every active exemption MUST appear in
either a per-group required_paths_regex OR the harness/shared-infra
full-run bucket; no exemption left unclassified.

§2 PM template description (line 141): 'All 78 entries' → 'PM-grouped
entries (PM template snapshot was 78 at template authoring time; live
count grows — Mgr re-verifies via wc -l at finalization, NOT this
stale historical reference)'. Added note that the 9-cluster taxonomy
survives count growth; Mgr maps new entries to existing clusters or
escalates if a new cluster surface emerges.

Brief is now internally consistent on inventory-count freshness:
- §0 line 19: live 80 with verification command
- §2 line 114: re-run command at finalization; explicit do-not-cite-78 instruction
- §2 line 141: PM template snapshot historical; live count grows
- §2 line 157 (Mgr-fill): re-run grep, don't trust stale citations

12th distinct review-class catch this polish cycle: inventory-citation
freshness as fail-closed completeness invariant.

* docs(briefs): §5 acceptance requires testclaim_references explicitly per codex BLOCKING #9780

codex REQUEST_CHANGES on PR #2719 sha 8ae7938 (review #9780):

Finding #1 (stale 78 at lines 114 + 141) already fixed at prior commit
487d175; codex finding overlaps with openai-pro #9779 absorbed before.

Finding #2 (new): §5 acceptance at line 228 only required dimensions:
Set<Dimension> on each group entry, NOT testclaim_references: Set<NodeRef>,
even though the brief makes that column load-bearing at:
- §0 line 104 (post-dissolution selection canonical 2-step)
- §3 line 178 (substantive paragraph: 3-column surviving schema)
- §8 line 269 (surviving artifact 3-column)

A Mgr reading §5 acceptance literally could call PR-set 'done' with
dimensions-only column population — that's the dimensions-only closeout
codex flags as facts-flow-forward violation.

Fix: §5 acceptance adds new explicit criterion:
'Every group entry has testclaim_references: Set<NodeRef> field' with
explicit citation chain (design §:359 + Brian BLOCKING #2 + codex
BLOCKING #9780). Includes bridge-tier-proxy vs post-dissolution-proxy
note. Includes 'Dimensions-only acceptance closeout is rejected: P2
facts-flow-forward requires both lens-join inputs.'

§5 acceptance now coherent with §0/§3/§8 on the 3-column surviving
schema; no path to 'done' that skips testclaim_references.

13th distinct review-class catch this polish cycle:
acceptance-vs-substantive-text divergence on load-bearing fields.

* docs(briefs): Director scaffold for cold-v3 rebuild coordinator (Phase 3-pattern; per-cut child workers)

Per PM greenlight msg_07f73de0 + Brian operator greenlight at gunbc#846
reply (~01:25Z 2026-05-12). Pre-authored scaffold per
feedback_pre_authored_brief_queue + feedback_director_mgr_energy_input;
activation triggers on empirical post-#2723 cold-v3 wall-clock measurement.

Scope: rebuild 20 hot-fix-2026-05-12-tagged cut tests under
OnceLock/cached_compile/shared-fixture amortization. Each rebuild PR:
- Removes #[ignore] attribute
- Retires slow-test-exemptions.txt row
- Decrements TEST_TIMEOUT_MAX_EXEMPTIONS in lockstep
- Verifies <2s wall on cold ubuntu-latest

Brief covers:
- §0 scope: full 20-test inventory grouped into 9 clusters (A-I) by
  lane + amortization affinity
- §1 mechanism: 4-step per-cut worker pattern (baseline, refactor,
  verify, re-enable + retire-exemption)
- §2 6 hard constraints (preserve semantics, ratchet-down per PR,
  amortization-mechanism-only, no new hand-Rust, per-cluster fidelity,
  re-enable-with-ratchet-down enforcement)
- §3 acceptance: per-PR + final cold-v3 ≤10min + ratchet floor ≤80
- §4 decomposition: pilot (Cluster A) → high-impact (Cluster H TC1
  140s) → parallel rollout → ratchet sweep
- §5 STOP-and-escalate criteria
- §6 cross-coordinator notes:
  - T-LAS Mgr seat gap (Cluster F) — Director surfaces ownership
  - Phase 3 #84 cluster overlap — Verification Mgr decides Layer 2
    rebuild PR vs Cluster M Phase 3 PR routing
  - Layer 2 brief #2719 INDEPENDENT — rebuild is structural regardless

Activation decision branch:
- post-#2723 cold-v3 >20min → second cut session
- 10-20min → rebuild alongside possible second-cut
- ≤10min → rebuild can de-prioritize

Per-cluster routing:
- A+I → PB Mgr (Lane 3 Stage 3c)
- B → Substrate Mgr (M1_5_DESIGN)
- C/D/E/G → Verification Mgr (this brief's coordinator)
- F (T-LAS) → Director-routed operator-tier (no standing Mgr seat)
- H (TC1 substrate-adjacent) → Substrate Mgr or dedicated session

Authority chain documented in footer.

* docs(briefs): absorb Brian + codex 3-finding BLOCKING wave (P5 receipts, dynamic ratchet floor, polarity-residual)

Brian inline BLOCKINGs + codex scheduled review BLOCKING #9XXX at PR #2725
sha 698ba61 (4 findings total; codex overlaps with all 3 Brian findings):

(1) #2725 line 70 (constraint #4) — shared-fixture helper carve-out
permits expanded hand-Rust under src/v3/compiler/tests without INVARIANTS
P5 receipt. Brian: P5 receipt required for new/expanded src/v3 Rust.
Codex: require P5 receipt OR state SG-0-neutral without helper expansion.

(2) #2725 line 83 (§3 acceptance final bullet) — hard-codes ratchet floor
≤80 (pre-hot-fix baseline), preserving stale debt. Brian: current main has
84 active exemptions with 20 hot-fix rows; post-rebuild floor should be
recomputed, not preserved at 80. Codex: derive final floor from live
non-hot-fix exemptions at Mgr finalization; delete hard-coded ≤80.

(3) #2719 line 217 (§4 hard constraint #5 Polarity invariant sub-bullet) —
restates skip formula as dimension-only, contradicting two-step
NodeRef+dimension contract. Brian: silently drops testclaim_references in
violation of P2 Facts Flow Forward. Codex: rewrite every formula to skip
when refs∩nodes empty OR dims∩changed_dims empty. (Partial-absorption-
residual: cursor's catch on #2725 review #9799 was fixed at §3 substantive
paragraph at commit 403833e but didn't propagate to §4 constraint #5
sub-bullet at line 217 — different polarity-mentioning site within the
same brief.)

Fixes (single-pass per discipline; same pattern as prior 14-catch cycle):

#2725 constraint #4 (line 70) rewrite:
- 'No new hand-Rust beyond shared-fixture helpers' (carve-out) →
  'Shared-fixture helpers require P5 receipt + SG-0-neutrality'
- Per-PR P5 receipt explicit: (a) helper LOC delta cited, (b) dissolution
  path named (helper retires when cluster's pattern lands in .dag
  TestClaim authority), (c) SG-0 census-delta computation showing net
  ≤ 0
- SG-0-neutrality enforcement: helpers may add lines but net delta ≤ 0
  (helper additions offset by exemption-row retirements + ratchet-down).
  Net positive = escalate (substrate-shape signal)

#2725 §3 acceptance final bullet (line 83) rewrite:
- 'ratchet floor returned to ≤80 (pre-hot-fix baseline)' → 'ratchet floor
  recomputed DYNAMICALLY from live state at activation'
- Concrete computation: starts at current main HEAD's
  TEST_TIMEOUT_MAX_EXEMPTIONS (84 at dfbc010; verify via grep at Mgr
  finalization); each rebuild PR decrements by N (cuts rebuilt that PR);
  post-all-20-rebuild target = (value at activation) - 20 (e.g., 64 at
  current state)
- Removed '≤80 pre-hot-fix baseline' framing
- Explicit acknowledgment: 80 was ITSELF stale debt; 16 non-hot-fix
  exemptions have separate paydown owners; rebuild does NOT freeze goal
  at 80; long-run target per feedback_pb_zero_is_r3_close_target is 0

#2719 §4 constraint #5 (line 217) rewrite:
- Header changed: '...dimensions: Set<Dimension> field on every group
  entry' → '...dimensions: Set<Dimension> + testclaim_references:
  Set<NodeRef> fields on every group entry'
- Polarity invariant rewritten to canonical 2-step join (BOTH NodeRef AND
  dimension intersections; skip = either empty)
- Two fail-open bug patterns explicitly named: (a) inversion (b)
  dimension-only collapse
- Bridge-tier proxy framing preserved (path-regex over-approximates
  canonical; fail-closed-safe coarseness)

15th + 16th + 17th distinct review-class catches this polish cycle (16
on #2719 brief; #15 on rebuild scaffold #2725):
- #15 (BLOCKING #1): shared-fixture helper P5 receipt obligation
- #16 (BLOCKING #2): dynamic ratchet floor recomputation
- #17 (BLOCKING #3): polarity-residual at second site (partial-absorption-
  residual within partial-absorption-fix; pattern: 'when canonical
  algorithm gets corrected, ENUMERATE all polarity-mentioning sites'
  is the discipline)

* docs(briefs): apply §3 polarity 2-step rewrite on rebuild-scaffold branch (cursor #9815 catch + #2719-branch parity)

cursor APPROVE_WITH_COMMENTS on #2725 review #9815 caught that line 208
(§3 substantive Polarity invariant paragraph) on rebuild-scaffold branch's
copy of #2719 brief was still dimensions-only — even though line 217 (§4
constraint #5 sub-bullet) was updated to canonical 2-step in commit
900d5a3.

Root cause: my prior #2719 polarity fix at commit 403833e was on #2719's
own branch (director/r3-ci-layer-2-path-conditional-gating-scaffold) and
never propagated to main → never reached rebuild-scaffold branch's copy
of the #2719 brief brought in via main-merge.

Applied same §3 polarity rewrite on rebuild-scaffold branch for parity
with #2719 branch's content:
- run = (refs ∩ nodes) ≠ ∅ AND (dims ∩ changed_dims) ≠ ∅
- skip = ¬run = either intersection ∅
- Explicit naming of TWO fail-open patterns: (a) inversion (b)
  dimension-only collapse
- Bridge-tier proxy framing preserved

Cross-branch state now consistent:
- #2719 branch (director/r3-ci-layer-2-path-conditional-gating-scaffold)
  has canonical 2-step at lines 208 + 229 (via 403833e)
- #2725 branch (director/r3-ci-cold-v3-rebuild-coordinator-scaffold) has
  canonical 2-step at lines 208 + 229 (via 900d5a3 + this commit)

Both branches' copies of #2719 brief now structurally identical on
polarity semantics. Will fully reconcile at merge time if both PRs land
separately.

18th distinct review-class catch this polish cycle:
cross-branch-divergence-on-shared-doc — when two Director-scaffold PRs
both touch a shared brief (one via direct edit, one via main-merge),
fixes on one branch must explicitly propagate to the other branch OR
the shared content reconciles at merge time. Pattern: 'shared doc in
two PRs requires explicit cross-branch parity discipline'.

* docs(briefs): fix Phase 4 ratchet sweep residual ≤80 → dynamic (value − 20) per codex BLOCKING #9827

codex BLOCKING on #2725 review #9827 caught residual at line 92 (§4 Phase 4
ratchet sweep description) — still said 'back to ≤80' despite §3 acceptance
bullet's stale-baseline correction (which removed the ≤80 framing in favor
of dynamic '(value at activation) - 20').

Same partial-absorption-residual class as cursor's earlier catches:
fixing the §3 acceptance bullet correction didn't propagate to §4 Phase 4
description; sites referring to the same stale value need parallel updates.

Fix: Phase 4 description now uses dynamic '(value at activation) − 20'
(e.g., 64 at current state of 84) with explicit acknowledgment that 80
was itself stale debt + cross-link to feedback_pb_zero_is_r3_close_target
naming the long-run target = 0 exemptions.

21st distinct review-class catch this polish cycle:
phase-description-vs-acceptance-bullet-residual — when an acceptance
bullet gets a corrected target, the phase descriptions that motivate
phases toward that target need parallel updates. Pattern: 'when target
gets corrected, ENUMERATE all phase descriptions / decomposition / STOP
criteria that motivate work toward that target.'

* fix(#2725): cursor BLOCKING #9834 absorbed

Two findings addressed:

1. Line 76 copy-paste slip: "The Layer 2 PR-set is acceptable when:"
   in a cold-v3 rebuild brief. Changed to "The cold-v3 rebuild PR-set
   is acceptable when:" to match brief's actual scope. INVARIANTS.md
   P1 modeling faithfulness for dispatch authority.

2. Line 70 prose tightening: SG-0-neutrality framing previously
   conflated SG-0 census mechanism with exemption-list mechanism
   ("helper additions offset by exemption-row retirements +
   ratchet-down"). These are DIFFERENT bookkeeping: SG-0 counts
   hand-Rust files/lines per sg0_census_test.rs; exemption-row
   retirement only reduces slow-test-exemptions.txt count. Corrected
   prose: helper-LOC additions in common/* MUST be offset by EQUAL-
   or-greater LOC reductions in per-test files consuming the helper
   (shared fixture extraction → per-test setup boilerplate dropped).
   Exemption-row retirement + ratchet-down are independent
   obligations per constraint #2 and do NOT count toward SG-0
   census-delta.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* fix(#2725): openai-pro REQUEST_CHANGES — 2 BLOCKING findings absorbed

Finding 1 (P3 Fail-Closed): Layer 2 shared-infra regex anchored Cargo.toml/
Cargo.lock/build.rs to workspace-root only. Crate-local manifests (e.g.,
src/v3/compiler/build.rs per CODING.md:319) would NOT match, silently
skipping tests for crate-local manifest/build-script changes — fail-open
boundary class P3 forbids. Fixed by changing the anchored alternates to
use (.*/)?Cargo\.(toml|lock) and (.*/)?build\.rs — non-capturing optional
path prefix matches both root-level AND any-depth crate-local files.

Finding 2 (ratchet/test discipline): Cold-rebuild brief had execution-path
contradiction. §2#2 + §3 require same-PR lockstep ratchet-down. But §4
Phase 4 description said "drops TEST_TIMEOUT_MAX_EXEMPTIONS to (activation)
- 20", creating a fail-open path where workers could defer per-PR ratchet-
down to Phase 4 cleanup. Reframed Phase 4 as VERIFICATION + budget-tighten
(NOT decrement). Phase 4 verifies cumulative ratchet matches target +
drops cold-CI --timeout. If verification finds mismatch, escalate per §5
(per-PR discipline violation), do NOT silently patch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Verified the cursor/composer-2 review 9866 against current head acf131e. The artifact says "Findings: None" and "Verdict: APPROVE"; the current diff remains a single docs/briefs canvas and the cited live-substrate note is still present. No code or doc change is warranted for this feedback item. — sent from clever-tern-670

briansrls added a commit that referenced this pull request May 12, 2026
* docs(briefs): R3 CI Layer 2 — PM pre-staged Mgr-fill template

Author the pre-staged Mgr-fill reference doc Director accepted via
msg_4623068b at 22:54Z (greenlight on PM's pre-staged-skeleton offer
from gunbc#828 c4425726922). Director will cite this file in their
forthcoming worker brief (`docs/briefs/r3-ci-layer-2-path-conditional-
gating-worker.md`) as the starting template for Verification Mgr
(clever-tern-670) inventory finalization.

Content:
- §1 affected-set lens Dimension enum reference (cite design doc §2)
- §2 slow-test inventory grouped into 9 clusters (78 entries from
  scripts/slow-test-exemptions.txt)
- §3 path-mapping skeleton table — (test_pattern, dimension,
  required_paths_regex, confidence, dissolution_note). PM partial-
  fills high-confidence rows; ~12 [Mgr-fill] placeholders left for
  rows requiring deeper substrate-lens / consumer-tracing knowledge
- §4 open questions for Mgr (multi-dim split, conservative defaults,
  pilot cluster selection — recommended Cluster B = Lane 2 Stage 2d
  symbolic cost; high-confidence single-dimension contained module)
- §5 acceptance checklist for Mgr-fill completion
- §6 STOP triggers (new substrate carrier need; dimension outside
  enum; test-output dependency = lens not bridge)
- §7 cross-refs (Layer 1 PR #2718, lens canvas PR #2713, routing
  msg_a77c7f42, memory feedback_parallel_representation_debt)

Hard constraint per feedback_parallel_representation_debt: every row
carries a dimension: field matching the lens Dimension enum so post-
dissolution skip_* flags compute structurally as
`affected_dimensions.contains(group.dimension)` — same enum,
structural source. Prevents path-mapping schema divergence from
future lens API surface.

Dissolution trigger: gate
ci_uses_provable_minimal_affected_set_selection (R3 close-blocking;
docs/design-affected-set-lens.md §5). When the lens lands, this
template + the worker output are deleted.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — dimensions is Set<Dimension>, not single primary (codex REQUEST_CHANGES fix on PR #2721)

codex REQUEST_CHANGES on PR #2721 (review #9707) caught a semantic-
contract violation: the template asserted "every entry carries exactly
one primary `dimension:`" and post-dissolution `skip_*` computation as
`affected_dimensions.contains(group.dimension)`. This conflicts with
the locked design at `docs/design-affected-set-lens.md` §2:

  affected_set(Dag_before, Dag_after) =
    ⋃ over dim in {Value, Cost, Complexity, Effect, Refinement}
      affected_set(Dag_before, Dag_after, dim)

A test that reads BOTH Cost AND Complexity (e.g., D-cluster LBP
demonstration; lane2_stage_2f composed-matches-lens) would be silently
skipped when only Complexity changes if its dimension is narrowed to
"Cost." That's `INVARIANTS.md` P2 single-authority violation against
the locked lens design.

Fixes:
- §1: rewrite from "exactly one primary dimension" to "dimensions is
  Set<Dimension> = full read-set; affectedness is union semantics"
- Header bullet: hard constraint reframed — multi-dim REQUIRED when
  consumer reads multi; post-dissolution math is `(affected ∩ row.dimensions) ≠ ∅`
- §3 table: column rename `dimension` → `dimensions`; rows updated:
  - D-cluster LBP, lens_cost_target_realization, cost_lens_consumer:
    expanded to multi-dim sets [Complexity, Cost], [Cost, Value]
  - lane2_stage_2f_dimension: [Complexity, Cost] (composed-matches-lens)
  - F-`m0_acceptance` + I-`thesis_validation_test`: full 5-dim set
    (compile-boundary + thesis-level read every dim)
  - G-`t_las_crdt_cost_basis_demo`: [Cost, Effect, Value]
  - G-`r3_free_consequences_second_batch`: [Cost, Value]
  - H-`t_ci_workflow_as_data_demo`: [Value, Cost] (DimensionReport timing)
  - All single-dim rows (A, B, Most-C, etc.): formatted as set `[Cost]`
- §4 Open question 1: rewrite to forbid narrowing, mandate ADD-when-doubt
- §5 acceptance: add dim-set-semantics + union-formula checks
- §6 STOP triggers: add "tempted to narrow set → STOP and EXPAND"

Director's Layer 2 brief at PR #2719 has the same singular-`dimension:`
shape and likely has the same finding waiting to surface; will flag to
Director after this lands.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template count + wording fixes (cursor BLOCKING #9719 on PR #2721)

cursor BLOCKING REVIEW on PR #2721 (review #9719 at dedcf69) caught
factual count discrepancies + the stale singular `dimension` echo
that openai-pro had flagged as non-blocking:

1. Cluster A banner — was "(~10)", actual sum = 1+6+2+6 = 15 → fixed to "(15)"
2. Cluster B individual-row count "6" while listing 7 names → fixed to 7;
   banner "(~6)" → "(7)"
3. emit_matrix Notes "5× emit matrix sweep" while listing 6 tests
   (3 module + 3 program) → fixed to "6× emit matrix sweep (3 module
   + 3 program)" for explicit attribution
4. Cluster D banner "(~5)", actual sum = 2+3+2+2 = 9 → fixed to "(9)"
5. Line 7 (Purpose) stale singular `(test_pattern, dimension,
   required_paths_regex)` echo → fixed to `dimensions` plural;
   converges with openai-pro APPROVE_WITH_COMMENTS observation (review
   #9714) that had been deferred to follow-up — cursor's BLOCKING
   verdict overrides the deferral

§4 Open question 5 (pilot recommendation) also corrected from
"~6 tests" to "7 tests" for Cluster B consistency.

Clusters C/E/F/G/H/I banner counts re-verified against table sums
(7/12/6/10/7/5 respectively) — all already exact, no change needed.

P1 Modeling Faithfulness restored: every cluster banner now matches
its enumerated tests-column sum.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — fix skip_<cluster> polarity (openai-pro BLOCKING #9721 on PR #2721)

openai-pro re-review on PR #2721 at sha 93080af caught a critical
boolean polarity inversion in the skip_<cluster> formula. A Mgr/worker
following the brief literally would have wired the CI gate backward,
silently skipping affected tests — TESTING.md "test selection must
not skip affected behavior" violation + Boundary Discipline violation
(boolean carrier name and contract encoded opposite meanings).

**The bug**: 4 places stated post-dissolution `skip_<cluster>` formula
as `(affected_dimensions ∩ group.dimensions) ≠ ∅` (skip when
intersection NON-empty), while the CI consumer wires
`if: skip_<cluster> != 'true'` (run when skip is NOT true). Combined:
when intersection is non-empty (= affected), skip=true → tests don't
run → affected tests silently skipped.

**The fix**: invert the formula to `(intersection = ∅)` (skip when
intersection IS empty = no affected dim that this cluster reads). The
CI gate semantics stay the same; the polarity correction is on the
post-dissolution lens mapping.

Sites corrected:
- §1 hard-constraint para (line 9): replaced "(non-empty intersection
  means run)" with an explicit Boolean polarity block defining
  `skip = (intersection = ∅)` and equivalent `run = (intersection ≠ ∅)`
- §3 path-mapping intro (was line 132, now 142): same polarity fix
  + "Equivalently: `run = (intersection ≠ ∅)`"
- §4 open-question 4 (was line 186, now 196): "skip_<cluster> becomes
  `(intersection ≠ ∅)`" → `(intersection = ∅)` with explicit
  "same polarity: skip when no affected dim" note
- §5 acceptance (was line 206, now 216): same polarity fix +
  explicit "inverting the polarity silently skips affected tests" warning

All 4 references now consistent. Polarity table:
  intersection = ∅  → skip=true  → "do not run" (NOT affected, safe to skip)
  intersection ≠ ∅  → skip=false → "run" (affected, must run)

Director's brief #2719 likely has the same polarity issue and will need
parallel fix from the same authority chain. Flagging separately.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — cluster aggregation + path-regex verification discipline (codex BLOCKING on PR #2721)

codex BLOCKING review on PR #2721 at sha 262f42d caught two
substantive gaps:

**(1) Cluster aggregation predicate missing**: §3 defined per-row
intersection check but didn't specify how multi-row clusters
aggregate to the cluster-level `skip_<cluster>` boolean. A worker
following the brief could implement disjunction (any-row-empty
= skip cluster) which would silently skip the OTHER affected rows
in the cluster when only one row is unaffected.

Fix: explicit conjunction predicate in §3 + §4 + §5 + §6:
  skip_<cluster> = ∀ row ∈ cluster : (changed_files ∩ row.regex) = ∅
Equivalently: run_<cluster> = ∃ row ∈ cluster : row affected.

**(2) Path regexes PM-authored without source-tree verification**:
PM concrete `required_paths_regex` values in §3 were manually
authored from the inventory SHA references without validation
against actual paths in the source tree. Workers might wire CI
gates against stale paths.

Fix: explicit Mgr-verification discipline in §3 + §4 + §5 + §6:
- Workers MUST validate each concrete regex against source tree
  at HEAD before CI implementation
- Unverified or unverifiable regexes → `.*` per conservative
  fail-closed default
- Confidence column treated as audit priority (low → `.*` first,
  medium → audit then decide, high → audit but likely fine)
- Validation record kept (PR description or commit message)

Both fixes preserve the locked-design polarity from earlier
revisions:
- Per-row formula stays `(intersection = ∅)` for skip semantic
- Cluster aggregation is conjunction over rows (∀)
- Run formula is the structural complement (∃ ↔ ≠ ∅)

All 4 places updated: §3 path-mapping skeleton intro + §4 mechanism
+ §5 acceptance + §6 STOP triggers. Brief now structurally
guards against:
- polarity inversion (skip = ∅, not ≠ ∅; openai-pro caught prior)
- dimension cardinality narrowing (Set<Dimension>, not single; codex
  caught prior)
- cluster aggregation by disjunction (∀, not ∃; codex caught this)
- regex authoring without source-tree validation (codex caught this)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — fix stale dsl/std/ lens-paths (codex BLOCKING inline at line 152)

codex BLOCKING inline-review at line 152 (sha 262f42d) caught
that Cluster B's regex used stale `dsl/std/lens_cost.*\.dag` +
`dsl/std/cost.*\.dag` paths while the live cost-lens authority
is at `src/v3/lenses/cost.dag`. A change to the live authority
file would NOT match the stale regex → skip_b=true → cost-lens
tests silently skipped (P3 fail-closed + P2 single-authority
violation).

**Systematic audit + fix**: stale `dsl/std/<lens>.dag` pattern
applied across many rows (PM authored assuming lens .dag lived
in dsl/std/, but the live tree has them at src/v3/lenses/):

| Row | Old (stale)                                    | New (verified)                                                 |
|-----|------------------------------------------------|----------------------------------------------------------------|
| B   | dsl/std/lens_cost.*.dag + dsl/std/cost.*.dag   | src/v3/lenses/cost(_target_realization)?.dag                   |
| C-i | dsl/std/lens_idempotency.*.dag                 | src/v3/lenses/idempotency.dag                                  |
| C-p | dsl/std/lens_provenance.*.dag                  | src/v3/lenses/(provenance\|emission_provenance).dag            |
| C-u | dsl/std/lens_unused_parameters.*.dag           | src/v3/lenses/unused_parameters.dag                            |
| E×4 | dsl/std/(complexity\|cost\|symbolic_cost).*.dag | src/v3/lenses/(complexity\|cost).dag                           |
| F-b | dsl/std/boolean_algebra.*.dag                  | dsl/std/logic.dag (boolean-algebra concepts live there)        |
| G-c | dsl/std/complexity.*.dag                       | src/v3/lenses/complexity.dag                                   |
| G-l | dsl/std/(cost\|las\|crdt).*.dag                | `.*` (Mgr-fill; T-LAS substrate-deps not PM-traced yet)        |
| H-2 | dsl/std/parse.*.dag                            | src/v3/std/parse_surface.dag + src/v3/compiler/parse_tables.dag|
| H-2c| dsl/std/parse_tables.*.dag + dsl/std/tokenize  | src/v3/compiler/parse_tables.dag + src/v3/(compiler\|std)/tokenize.dag |
| H-w | dsl/std/workflow.*.dag                         | src/v3/std/workflows.dag                                       |

Confidence column dropped from `high` to `medium` for all
post-correction rows — Mgr should still validate each path
against live source tree at HEAD before CI implementation per
the verification-discipline added at d19a1a0. dissolution_note
column carries inline "**Path correction**: ..." annotations
documenting each fix for reviewer audit.

Cross-cluster bug-class catches now mapped on this template:
1. Dimension cardinality (Set<Dimension>; dedcf69)
2. Boolean polarity (skip = ∅; 262f42d)
3. Count discrepancies + line-7 singular (93080af)
4. Cluster aggregation predicate (∀ not ∃; d19a1a0)
5. Path-regex verification discipline (d19a1a0)
6. **Stale dsl/std/ lens-paths corrected to src/v3/lenses/** (this fix)

Brief structurally validated across 6 distinct axes.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — fix regex alternation escape (openai-pro APPROVE_WITH_COMMENTS on #2721)

openai-pro APPROVE_WITH_COMMENTS on PR #2721 at sha 45fc195 caught
a non-blocking regex error: line 185 had `src/v3/(compiler\|std)/tokenize.dag`
with `\|` (markdown-cell pipe escape), which a regex engine would
interpret as the literal string `compiler|std`, NOT as alternation
between `compiler` and `std`.

Mechanism of the bug:
- Markdown tables use `|` as column separator
- To put a literal `|` IN a cell (outside backticks), you escape with `\|`
- PM authored the regex with `\|` thinking the markdown-table escape
  was needed, but the regex is INSIDE backticks (code span) which
  preserves pipe character literally
- A worker copying the regex into ci.yml would silently miss
  tokenize.dag changes (only matches literal `compiler|std/tokenize.dag`)

Fix: drop the unnecessary `\` escape; markdown code spans preserve
`|` literally. Now regex correctly reads
`src/v3/(compiler|std)/tokenize.dag` — alternation between
src/v3/compiler/tokenize.dag and src/v3/std/tokenize.dag, both of
which exist per the source tree verified at 45fc195.

Mitigation: the template's own validation discipline at §3 + §5 §6
(workers MUST validate regex against live source tree before CI
implementation) would have caught this, but per openai-pro's read
"the concrete row should still not carry a known-bad example" — fair.

Cumulative bug-class catches on this template now 7 axes hardened:
1. Dimension cardinality (Set<Dimension>; dedcf69)
2. Boolean polarity inversion (skip = ∅; 262f42d)
3. Count discrepancies + line-7 singular (93080af)
4. Cluster aggregation predicate (∀ not ∃; d19a1a0)
5. Path-regex verification discipline (d19a1a0)
6. Stale dsl/std/ lens-paths corrected (45fc195)
7. Markdown-cell-escape leaking into regex semantics (this fix)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — Dimension enum is OPEN per design §2 + THESIS user-defined dims (codex BLOCKING on PR #2721)

codex BLOCKING inline-review at line 186-ish caught that my §6 STOP
trigger hard-rejected any `dimensions:` element outside the built-in
base set `{Value, Cost, Complexity, Effect, Refinement}` — which closes
the user-extensibility surface that THESIS + docs/design-affected-set-
lens.md §2 leave intentionally open with the trailing `...`.

Verification (codex was correct):

- `docs/design-affected-set-lens.md` §2: `⋃ over dim in {value, cost,
  complexity, effect, refinement, ...}` (note ellipsis = open enum)
- `THESIS.md` "User-defined dimensions" section: 'User-declared
  dimensions extend the same structural proof surface ... the ceiling
  of what gunbc can prove is user-extensible.'

The built-in base set ≠ the full enum. My template was treating them
as equivalent, which would have rejected valid user-defined dims at
the STOP gate (INVARIANTS P1 single-authority violation against
THESIS/design + P3 fail-closed violation since rejection-instead-of-
fail-closed is the opposite of safety).

Fixes:
- **§1** Dimension enum reference: rewrote with explicit `Dimension =
  {value, cost, complexity, effect, refinement, ...}` notation + the
  trailing `...` annotated as "OPEN for user-defined" + paragraph on
  THESIS user-extensibility framing + explicit instruction to treat
  unknown dim as fail-closed (always-run), NOT reject
- **§5** acceptance criterion: updated to reference the open enum +
  fail-closed-for-unknown behavior
- **§6** STOP trigger: now reads "cannot be carried as a typed
  Dimension at all (e.g., string-as-dimension, runtime-only)" — that's
  the genuine structural failure. Encountering a NEW user-defined
  dimension is NOT a STOP; it's a row carried as fail-closed-always-run

Cumulative bug-class catches on this template now 8 axes hardened
(was 7 before this fix; ci-skip-pattern-script wasn't applicable here):
1. Dimension cardinality (Set<Dimension>; dedcf69)
2. Boolean polarity inversion (skip = ∅; 262f42d)
3. Count discrepancies + line-7 singular (93080af)
4. Cluster aggregation predicate (∀ not ∃; d19a1a0)
5. Path-regex verification discipline (d19a1a0)
6. Stale dsl/std/ lens-paths corrected (45fc195)
7. Markdown-cell-escape leaking into regex semantics (7cbf29f)
8. **Dimension enum hard-closed rejecting user-defined** (this fix) —
   THESIS + design doc §2 explicitly leave open

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — carry user-defined Timing dim explicitly (codex BLOCKING on PR #2721)

codex BLOCKING re-review at sha c61a7ed line 197 (~193 in their
relay) caught a narrowing residual after the prior open-enum fix:
the `t_ci_workflow_as_data_demo_test` row carried `[Value, Cost]`
but the test actually evaluates `DimensionReport<TimingMeasurement>`
/ `ci_modeled_timing` — a user-defined Timing dim distinct from
generic Cost.

My prior open-enum fix (c61a7ed) updated §1/§5/§6 to ALLOW user-
defined dims but I didn't fix THIS row to USE one. Per the just-
established 'carry the dim, don't narrow' framing in §6, this row
should carry `[Value, Cost, Timing]` (or just `[Value, Timing]` if
Cost is sufficiently distinct from Timing in the test).

**Why it's load-bearing**: a future timing-only delta (e.g.,
DimensionReport schema change touching only timing fields, not Cost)
would be 'affected' for this test under the lens but the prior row
narrowed Timing → Cost → if Cost.affected = empty but Timing.affected
non-empty, test would be silently skipped (TESTING.md violation +
THESIS user-defined-dims framing violation).

Fix:
- Row dimensions: `[Value, Cost]` → `[Value, Cost, Timing]`
- Row dissolution-note: explicit annotation citing
  `DimensionReport<TimingMeasurement>` + `ci_modeled_timing` user-
  defined dim + the carrying-vs-narrowing rationale
- Self-references this template's own open-enum support per §1 —
  the row is now an in-table demonstration of the open-enum framing
  (consistency between framing and example)

This also re-stress-tests cluster aggregation: cluster H aggregates
over multiple rows including this Timing-carrying row, so cluster-
level skip computation correctly fail-closes when ANY row's dim
intersects with affected_dims.

Cumulative bug-class catches on this template now 9 axes hardened:
1. Dimension cardinality (Set<Dimension>)
2. Boolean polarity inversion (skip = ∅)
3. Count discrepancies + line-7 singular
4. Cluster aggregation predicate (∀ not ∃)
5. Path-regex verification discipline
6. Stale dsl/std/ lens-paths corrected
7. Markdown-cell-escape regex
8. Dimension enum hard-closed (open per THESIS)
9. **Narrowing user-defined dim to built-in** (this fix; carry don't normalize)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — codify 3-arm regex completeness invariant (mirror Director PR #2727 worker-brief discipline)

Director's PR #2727 absorbed Brian inline + codex BLOCKING convergent
finding on post-#2719 fail-open hole: per-group regex must include
THREE arms — deps + test-source + fixture — missing any is a
P3 fail-open boundary class.

This template (PR #2721) had the same structural issue: most PM-
authored rows have arms (1) deps + (2) test-source but lack arm (3)
`tests/dag/*.dag` fixture explicitly. Per Director's canonical
worker-brief discipline (PR #2727), this mirrors the gap and adds
the 3-arm completeness invariant to align.

Updates:
- §3 path-mapping intro: explicit 3-arm completeness invariant + per-
  arm fail-open semantics + audit note that PM-authored rows in §3
  below need Mgr fixture-arm audit for tests reading from
  `tests/dag/*.dag` (e.g., `t_pb_b_1_dag_runner_test` consumes
  `tests/dag/t_pb_b_1_*.dag`)
- §5 acceptance: new checklist item — every concrete regex includes
  arms (1) + (2) + (3) where applicable; Mgr-fill rejects missing
  arms 2/3
- §6 STOP triggers: two new STOP triggers for missing test-source
  arm OR missing fixture-arm-when-applicable
- Cross-link to Director PR #2727 / #2719 for canonical framing

This codifies but does NOT retrofit existing §3 rows — that's
Mgr-fill audit work (per the §3 disclaimer + Mgr-fill discipline).
PM signals the gap; Mgr fixes per row.

Cumulative bug-class catches on this template now 10 axes:
1. Dimension cardinality (Set<Dimension>)
2. Boolean polarity inversion
3. Count discrepancies + line-7 singular
4. Cluster aggregation predicate (∀ not ∃)
5. Path-regex verification discipline
6. Stale dsl/std/ lens-paths
7. Markdown-cell-escape regex
8. Dimension enum hard-closed (open per THESIS)
9. Narrowing user-defined dim (Timing→Cost)
10. **Missing test-source/fixture arms in regex** (this fix mirroring
    Director PR #2727 worker-brief discipline)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — restore `...` ellipsis in quoted §2 union formula (cursor APPROVE_WITH_COMMENTS-level exploratory on PR #2721)

cursor APPROVE review #9858 at sha 5c227c5 noted an exploratory
inconsistency: my quoted design-doc §2 union formula at lines 48-51
enumerated only the 5 built-in dimensions without the trailing `...`
that the actual `docs/design-affected-set-lens.md` §2 has, while my
surrounding text (lines 27-33, §1 enum reference) stresses the open-
enum framing.

Fix: restore the `...` in the quoted formula + add inline annotation
'← OPEN per §2; user-defined dims extend' so Mgr-fill readers can't
misread the box as closed.

Now lines 27-33 (open-enum framing) + lines 48-51 (formula quote) +
§5 acceptance + §6 STOP triggers all consistently affirm the open-
enum framing per THESIS user-defined dimensions.

Non-blocking exploratory observation; quick fix because the cost is
trivial (1-char + comment) and the value is internal-consistency
preservation.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Verified the OpenAI Pro review #9868 against current PR state. The posted review on PR #2713 says APPROVE and finds the docs-only canvas compliant with substrate authority, fail-closed escalation, no new Rust analysis, tests-as-data, and executable receipts. The current PR diff remains a single docs/briefs canvas and GitHub checks are green. No code or doc change is warranted for this feedback item. — sent from clever-tern-670

@briansrls

Copy link
Copy Markdown
Contributor Author

Verified the Codex review #9884 against current head ee62573. The finding was valid at sha b598a73 and is fixed in ca3c6f0: §3 now seeds both PROVEN deltas and nodes whose dimension delta cannot be proven empty, and excludes only with a receipt proving delta(dim) == empty. Current lines 60-65 match the fail-closed design rule, and GitHub checks are green on the current head. — sent from clever-tern-670

@briansrls
briansrls merged commit e5c00b8 into main May 12, 2026
5 checks passed
@briansrls
briansrls deleted the session/clever-tern-670-affected-set-canvas branch May 12, 2026 03:56
briansrls added a commit that referenced this pull request May 12, 2026
…2744 §1 (#2750)

* docs(r3): T-WAD FULL R3 §1.8 ledger sync — +6 gates (#98–#103) per PR #2744 §1

**Authority**: PM scoping doc PR #2744 §1 (T-WAD FULL R3 elevation per operator
directive 2026-05-12 + Director ratification msg_5cbdad24 + msg_f9fd669e + (b)
ledger-sync disposition msg_2a68a4b5 — follow-up sync PR pattern).

**Sync disposition rationale** (per Director msg_2a68a4b5): option (a) bundles too
much into PR #2744 mid-review; (c) bakes parallel-authority into scope doc as
"temporary" PROPOSED state which calcifies. (b) is operationally clean if sync
PR queues for atomic-merge-sequencing alongside PR #2744 — gap window bounded
to merge-clock seconds.

**6 new §1.8 gate rows** (all T-Workflow-As-Data, NEW 2026-05-12):

- **#98** `ci_yml_hand_authority_dissolved` (state-check) — hand-authority NOT
  file-deletion; (a) absent / (b) emission-artifact / (c) thin-shim per
  briansrls BLOCKING #PR2744 fix
- **#99** `emission_target_open_enum_landed` (substrate-shape) — EmissionTarget
  sum-type per (c-refined) shape at PR #2749 §7
- **#100** `project_github_actions_landed` (substrate-shape) — projection
  function declaration in gunbc namespace; consumes extdeps.github.actions.Workflow
  as codomain + CIWorkflowDag (PR #2736 carrier) as input domain
- **#101** `test_cost_dimension_landed` (substrate-shape) — Cost dimension on
  TEST NODES (distinct from existing compiler-internal cost gates
  #37/#39/#40/#70/#80 which are about SymbolicCost as the compiler's cost lens;
  this gate is about Cost-as-Dimension applied to test nodes so slow-test
  ratchet derives structurally)
- **#102** `slow_test_exemptions_dissolved` (state-check) — scripts/slow-test-
  exemptions.txt deleted; sibling of #101 per kernel-modeling discipline split
- **#103** `ci_uses_affected_set_selection` (state-check) — BinaryShim emitter
  consumes affected-set lens output from PR #2713; Layer 2 path-regex `if:`
  gates removed; cross-tier co-owned with clever-tern-670 Slice 7

**Count updates** (was 97 enumerated / 96 R3-load-bearing; now 103/102):

- §1.5 total enumeration: 97 → 103
- §1.5 R3-load-bearing arithmetic: 96 → 102 (= 103 - 1 canvas-deferred {#11})
- §1.5 composition tally: T-Workflow-As-Data 4 → 10 (+6 NEW)
- §1.5 prose: R3 close target 96 → 102
- §1.5 R4-carved-dissolved framing: target 96 → 102
- §1.7 status-taxonomy lead: 96 → 102 R3-load-bearing
- §1.8 standing-program note: 96 → 102 load-bearing
- §0 R3 close criteria: 97/96 → 103/102
- §1 plan-declared count: 97 → 103
- §1.6 acceptance criteria: 97/96 → 103/102
- §1.8 §1.8 single-canonical-view: 97 → 103
- §1.8 row #11 canvas-deferral arithmetic: 97 → 103
- §Q1 table: 97 → 103 + history pointer

**Sequencing discipline** (per Director msg_2a68a4b5):
1. This sync PR sits ready-to-merge until PR #2744 lands
2. As soon as PR #2744 squash-merges, fire this sync PR squash-merge immediately
3. Gap window: bounded to merge-clock seconds (atomic-as-possible without bundle)
4. If reviewer delay accumulates here, fold into PR #2744 retroactively (option (a)
   escalation path)

**Cost-dim distinction note** (per Director verification flag): existing gates
#37/#39/#40/#70/#80 are about compiler-internal SymbolicCost (cost lens reading
target programs). #101 is structurally distinct — Cost dimension on TEST NODES
for slow-test ratchet derivation. Not a duplicate.

**§1.9 acceptance-aggregator pilot row** (`t_ci_wad_full_r3_close`): remains in
PR #2744 §9 with gate-name references per `feedback_no_snapshot_integers_in_briefs`
discipline. No row added to this sync PR per Director msg_2a68a4b5 ("EITHER PR
#2744 §9 OR sync PR — your call; either works").

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): cross-doc authority sync — add 6 NEW T-WAD gates to r3-structure.md §Acceptance

Per codex BLOCKING review on PR #2750 (2026-05-12T07:34:59Z): scope doc lines
13 and 84 claim r3-structure.md was "updated in this PR" + reference 103-gate
total per r3-structure.md §Acceptance, but the PR only changed r3-program-plan.md
— r3-structure.md still had no #98–#103 rows. That violated INVARIANTS.md P2 /
modeling-discipline.md Practice 5 (single-authority metadata) — the closure
ledger became internally inconsistent at the canonical-source level.

Fix: add the 6 NEW gate bullets to r3-structure.md §Acceptance T-Workflow-As-Data
section (after `ci_workflow_modeled_as_dag`), mirroring r3-program-plan.md §1.8
rows #98–#103. Each bullet carries the full Pass-condition body (single-source
authority for Pass conditions per the r3-program-plan.md convention).

Now both docs land the same gate set atomically in this PR:
- r3-program-plan.md §1.8 rows #98–#103 (commit ef9a140, prior)
- r3-structure.md §Acceptance T-WAD bullets (this commit) — matching content

The "Documentation Describes Live State" rule + single-authority discipline
restored.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): briansrls BLOCKING fix — propagate 103/102 counts through full plan

Per briansrls BLOCKING inline review on PR #2750 at line 84 (2026-05-12T07:50:26Z):
"The new 103/102 canonical count is not propagated through the full plan,
leaving later close criteria at 96/97 and creating competing R3 thresholds
(INVARIANTS P2 single authority)."

Three stale references found in re-grep + fixed:

- Line 114 (§1.7 two-Pass-surfaces context): "**96** R3-load-bearing gates
  green" → "**102** R3-load-bearing gates green" (post-carve-promotion +
  T-WAD FULL R3 elevation)
- Line 623 (§5.2 R3 close definition): "**96** load-bearing post-carve-
  promotion" → "**102** load-bearing post-carve-promotion + T-WAD FULL R3
  elevation"
- Line 1001 (§10 dependency-graph mirror): "lane TestClaim gates (97 total)"
  → "lane TestClaim gates (103 total; 102 R3-load-bearing post-T-WAD-FULL-
  R3-elevation 2026-05-12)"

Initial sync (commit ef9a140) updated §0 + §1.5 + §1.6 + §1.7 + §1.8 + Q1
table; this commit completes propagation through §1.7 two-Pass-surfaces /
§5.2 R3 close definition / §10 dependency-graph mirror.

Single-authority discipline (INVARIANTS P2) now consistently asserts 103/102
across the full plan; no competing R3 thresholds remain.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): InlineGunbc DESIGN-ONLY alignment — cross-doc consistency with PR #2744 openai-pro BLOCKING fix

Per openai-pro BLOCKING fix on PR #2744 (commit e43aba3): WI-1 / WI-2 briefs
+ scope doc §2 type sketch all align on InlineGunbc as DESIGN-ONLY (NOT in
initial enum, lands when runtime consumer exists). The §1.8 gate bodies in
r3-program-plan.md row #99 + r3-structure.md §Acceptance bullet for
emission_target_open_enum_landed were stale relative to that alignment.

Fix in this sync PR:
- r3-program-plan.md §1.8 row #99: "(YamlStatic | BinaryShim | PythonShim |
  InlineGunbc | ...)" → "3 initial arms (...)" + InlineGunbc DESIGN-ONLY note
  with PR #2746 §5.4 + openai-pro BLOCKING cross-references
- r3-structure.md §Acceptance T-WAD bullet for emission_target_open_enum_landed:
  same change pattern

Single-authority across:
- PR #2744 scope doc §0 / §1 gate row / §2 type sketch
- PR #2744 WI-1 brief DESIGN-ONLY discipline
- PR #2744 WI-2 brief Output / DO-DON'T / Acceptance gates
- PR #2750 (this PR) §1.8 ledger row + §Acceptance archive
- PR #2746 §5.4 canonical DESIGN-ONLY framing

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): T-WAD ledger sync — lane-definition gate lists pointer-only + scope-doc cross-ref qualifier (codex BLOCKING + non-blocking on PR #2750)

Two findings from codex review #10042 on commit 0c08f77 (T-WAD ledger
sync PR head):

BLOCKING — "T-WAD ledger sync updated the Acceptance archive but skipped
the lane-definition gate lists → update those T-Workflow-As-Data gate
lists to include #98–#103 or make them pointer-only."

The PR #2750 cascade landed the 6 NEW T-WAD FULL gates (#98–#103) in:
- r3-structure.md §Acceptance T-Workflow-As-Data bullets (lines 172-177)
- r3-program-plan.md §1.8 ledger rows
- r3-program-plan.md count propagation (§0/§1.5/§1.6/§1.7/§5.2/§10/§Q1)

But the cascade missed two lane-DEFINITION gate lists in r3-structure.md
that ALSO enumerate T-WAD closure gates:
- Line 41 (numbered lane list, T-WAD entry)
- Line 222 (T-WAD row in §"Lane structure" table)

Both listed only the original 4 pre-FULL gates
(workflow_substrate_carriers_landed / timing_lens_carrier_landed /
ci_workflow_modeled_as_dag /
shared_external_attachment_pattern_documented). Reviewers reading
either list would not see the 6 NEW gates — INVARIANTS P2
single-authority gap.

Fix: convert both lane-definition lists to pointer-only references back
to §Acceptance T-WAD as the canonical gate list. Rationale: §Acceptance
is the authority anchor (per INVARIANTS P2 + sister r3-program-plan.md
§1.8); duplication in lane-definition lists would re-introduce drift
the cascade is closing. Also augmented both lane-definition entries
with FULL R3-close elevation 2026-05-12 framing + multi-Mgr ownership
(Substrate Mgr Slices 4-5/8 + Verification Mgr Slice 7 affected-set +
Debt-Paydown Mgr Slice 6 sub-component).

Non-blocking — "Line 172 cites
docs/r3-t-workflow-as-data-full-r3-close-scope.md, but git
ls-tree origin/main returned no blob → replace with existing receipt
or land the scope doc."

The scope doc exists on PR #2744's branch (in flight) but not on
origin/main yet. Codex correctly notes the dangling cross-reference
against current main. Fix: add explicit "(scope doc landing via
in-flight PR #2744)" qualifier so future readers know the citation
is forward-referencing a known in-flight PR rather than a typo or
missing doc.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): T-WAD ledger sync — remove dangling file refs (briansrls BLOCKING + codex INVARIANTS P2/P5 escalation on PR #2750)

briansrls inline BLOCKING at r3-structure.md:172 (2026-05-12T09:28:04Z)
escalated the prior non-blocking scope-doc citation issue to BLOCKING:

  "The new gate cites docs/r3-t-workflow-as-data-full-r3-close-scope.md
   section 1, but git ls-tree origin/main produced no blob and the
   reconstructed PR-head test returned 1, so the cited T-WAD scope
   authority is absent (INVARIANTS P2/P5)."

The earlier qualifier fix ("scope doc landing via in-flight PR #2744")
acknowledged the dangling reference but didn't resolve the structural
P2/P5 violation — the gate description still CITED an authority that
doesn't exist on origin/main, which is the merge target.

Audit: grepped both docs for refs to files that don't exist on
origin/main:
- docs/r3-structure.md:172 — `docs/r3-t-workflow-as-data-full-r3-close-scope.md` (PR #2744)
- docs/r3-program-plan.md:326 — `docs/briefs/r3-t-wad-full-r3-cidag-scaffold-worker.md` (PR #2744)

Fix: replace both file-path references with PR-number anchors. PR
numbers are stable references; file paths become valid only post-merge.
Gate descriptions are self-contained without the cross-references
(the (a)/(b)/(c) enumeration + supporting framing already conveys the
gate's substance).

- r3-structure.md:172: "per `docs/r3-t-workflow-as-data-full-r3-close-scope.md` §1 — scope doc landing via in-flight PR #2744" → "in-flight scope authority at PR #2744 §1"
- r3-program-plan.md:326: "WI-2 implementation: `docs/briefs/r3-t-wad-full-r3-cidag-scaffold-worker.md`" → "WI-2 implementation: in-flight via PR #2744 (brief lands with the scope-doc)"

Both gates retain full substantive content; only the file-path crutches
are removed. When PR #2744 merges and the files exist on main, future
authors may re-add file refs cleanly — but the gate descriptions never
needed them as load-bearing authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): T-WAD ledger sync — EmissionTarget → WorkflowRuntime rename cascade (warm-wolf-698 PR #2749 commit 575eb7e; SELF_HOSTING.md:609 name collision)

Cascade sister-PR rename: PR #2744 branch carries the scope-doc + brief
renames in commit 70a49ac; this commit carries the ledger / structure
gate-ID renames.

warm-wolf-698 surfaced a DECISIVE name-collision finding at PR #2749:666
/ :672 (briansrls operator BLOCKING 2026-05-12T09:26:49Z): the canvas
EmissionTarget sum-type collides with the canonical Shape-A carrier
declared at `src/v3/SELF_HOSTING.md:609`:

  type EmissionTarget {
    language: LanguageSpec       // what's valid (required)
    rendering: RenderingSpec?    // how to format (optional)
  }

This is the SELF_HOSTING.md emitter-composition authority — INVARIANTS
P2 violation. warm-wolf-698 pushed rename to WorkflowRuntime in PR
#2749 commit 575eb7e (48 occurrences). All OTHER ratified elements
stand per feedback_pre_compaction_framings_self_supersede.

This commit cascades the rename through PR #2750 branch:

- docs/r3-program-plan.md §1.8 row #99:
  gate ID emission_target_open_enum_landed → workflow_runtime_open_enum_landed
  (also EmissionTarget references in row description)
- docs/r3-program-plan.md §1.8 row #100:
  EmissionTarget references in project_github_actions signature
- docs/r3-structure.md line 41 (T-WAD lane summary):
  EmissionTarget references + gate-ID rename in the multi-gate reference
- docs/r3-structure.md §Acceptance T-Workflow-As-Data bullets:
  gate-ID emission_target_open_enum_landed → workflow_runtime_open_enum_landed
  EmissionTarget references in `project_github_actions_landed` description
- docs/r3-structure.md §Lane structure T-WAD row:
  EmissionTarget references in scope expansion text

Variant names unchanged (YamlStatic / BinaryShim / PythonShim). Gate
descriptions retain full substantive content; only the type-name and
gate-ID identifiers are renamed.

Cascade trail across in-flight PRs:
- PR #2749 (warm-wolf-698): 575eb7e — substrate canvas rename
- PR #2751 (warm-wolf-698): expression-substrate canvas rename (in flight)
- PR #2744 (mine): 70a49ac — scope-doc + WI-1 + WI-2 brief rename
- PR #2750 (mine): THIS COMMIT — ledger + structure rename
- PR #2745 (cool-carp-720): surfaced; WI-2 implementation needs realign
- PR #2746 (MERGED): docs/design-ci-workflow-emitter-dispatch.md needs
  follow-on rename PR (post-cascade-clear)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
…evation) (#2744)

* docs(scope): T-Workflow-As-Data FULL R3-close scope (operator elevation 2026-05-12)

Author PM scoping doc + 2 worker briefs for T-CI-Workflow-As-Data
elevation to FULL R3-close per operator directive 2026-05-12.

FULL scope vs existing T-WAD plan:
- ALL CI workflow authored as .dag (not just demo)
- Hand-authored .github/workflows/ci.yml DELETED (replaced by
  static-regen or thin shim invoking compiled binary)
- EmissionTarget toggle proven (YamlStatic + BinaryShim emitters
  emit from same ci.dag; operator-ratified toggle design)
- Affected-set integration via BinaryShim (Layer 2 path-regex
  bridge dissolved; consumes PR #2713 affected-set lens output)
- Cost dimension on test nodes (slow-test-exemptions.txt dissolved)

Proposed §1.8 gate additions (Director ratifies):
- workflow_emission_target_toggle_proven (NEW)
- ci_yml_dissolved (NEW)
- ci_uses_affected_set_selection (NEW)
- test_cost_dimension_landed (NEW)
- #56 expanded to ALL workflow (not just demo)

Slice expansion: existing Slices 1-3 + NEW Slices 4-8 (emitters,
Cost dim, affected-set integration, ci.yml deletion). Dependency
graph captured at §4; immediate parallel work at §6 (WI-1
emitter-dispatch canvas + WI-2 ci.dag scaffold).

Routes to: Director (zesty-bear-812) for FULL scope ratification;
Substrate Mgr (warm-wolf-698) absorbs Slices 4-5/8; Verification
Mgr (clever-tern-670) absorbs Slice 7 (affected-set integration);
Debt-Paydown Mgr (zesty-boar-261) absorbs Slice 6 sub-component
(slow-test-exemptions dissolution).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(scope): T-WAD FULL R3 — Director ratification absorbed + codex BLOCKING #9970 fix

Two-fold update:

(1) Director ratification msg_5cbdad24 2026-05-12 absorbed:
- FULL R3-close scope RATIFIED (operator directive aligns with #846
  c#4412330468)
- Gate framing: GATE-ADDITIVE (NOT scope-expand #56); 4 NEW gates
  per §1 (workflow_emission_target_toggle_proven, ci_yml_dissolved,
  ci_uses_affected_set_selection, test_cost_dimension_landed)
- Owner-Mgr: LANE-ABSORB to Substrate Mgr (warm-wolf-698) with
  T-CI-WAD program-tag; no dedicated T-CI-WAD Mgr spawn
- Sequencing endorsed (T-LBP gate for Slice 2; Phase 3 Cluster M
  gate for Slice 6)
- §9 acceptance-aggregator pilot parked (Director-flagged; not
  blocking; surfaces at next Director cadence tick)

(2) codex BLOCKING #9970 fix — carrier hierarchy:

Earlier draft instructed worker to model CI as
`Workflow<Trigger, Steps, Resources>` generic + each ci.yml `job`
becoming a `Step` + `needs` as Step dependency edges. This
contradicts single authority at `dsl/extdeps/github/actions.dag`:

- `:21` `Workflow` is CONCRETE type (not generic); has fields
  `name` / `on: List<WorkflowTrigger>` / `jobs: List<Job>` / `env`
  / `permissions`
- `:24` Workflow contains `jobs: List<Job>` (NOT steps directly)
- `:110` `Job` is the per-ci.yml-job carrier
- `:114` Each Job contains `steps: List<Step>` (Step is per
  ci.yml-step, NOT per-job)
- `:115` `Job.needs: List<String>` — job-id references (NOT
  step-level dependency edges)

Corrected mapping: ci.yml `job:` → `Job` node; `needs:` → Job-level
job-id list; per-job `steps:` → `Job.steps: List<Step>`. Hierarchy
preserved (Workflow > Job > Step), not flattened.

Slice state corrections:
- Slice 1 substrate LANDED via PR #2160 + #2169 (NOT held as
  earlier draft stated); WorkflowSecret + CronSchedule available
- Slice 3 demo LANDED via PR #2371 (t_ci_workflow_as_data_demo.dag
  + integration tests)
- `dsl/gunbc/ci.dag` already exists (PR #2371); WI-2 work is to
  EXTEND this file to cover full ci.yml, not create from scratch
- Path correction: WI-2 output is `dsl/gunbc/ci.dag` (extend),
  not `dsl/extdeps/github/ci.dag` (incorrect new-file path)

EmissionTarget field placement made OPEN (3 evaluated options in
WI-1 canvas: Workflow / CIPipeline / wrapper); operator-ratified
shape is "modeled toggle field" — substance is that the choice
is modeled data, not where it lives.

Citation chain: feedback_audit_adjacent_authority_first +
feedback_carrier_name_vs_contract_audit — should have grepped
existing carriers before authoring brief framing. Lesson
re-validated at PR cycle (codex catch on first PR-review pass).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(scope): fix Slice 1 cron carrier naming (CronExpression → CronSchedule)

cursor APPROVE_WITH_COMMENTS review #9960 caught factual-grounding
mismatch: §0 referenced Slice 1 as landing 'WorkflowSecret +
CronExpression' carriers, but §3 + actions.dag + landed substrate
at dsl/extdeps/cron_schedule_model.dag use 'CronSchedule'.

CronExpression was the Slice 1 worker brief naming
(docs/briefs/r3-substrate-t-workflow-as-data-slice-1-worker.md);
CronSchedule is the actual landed carrier name at HEAD via PR #2160
+ #2169 refinement. Doc updates §0 to use grounded name with
explicit 'superseded' note so workers don't chase the wrong type
label.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs+scope): T-WAD FULL R3 (c-refined) cascade — §1/§9 gate-set + WI-2 re-brief

§1 gate table revised to 7 rows (#56 demonstration + 6 NEW per Director msg_f9fd669e):
- ci_yml_deleted (state-check) — was ci_yml_dissolved
- emission_target_open_enum_landed (substrate-shape) — split from workflow_emission_target_toggle_proven
- project_github_actions_landed (substrate-shape) — NEW; (c-refined) projection function authority
- test_cost_dimension_landed (substrate-shape only) — split from sibling
- slow_test_exemptions_dissolved (state-check) — sibling split per kernel-modeling discipline
- ci_uses_affected_set_selection (state-check) — KEPT per Director clarification msg_f9fd669e

§9 aggregator pilot revised depends_on: #56 + 6 NEW (was #56 + 4 NEW); row SHAPE-STABLE post (c-refined) ratification.

WI-2 brief rewritten to (c-refined) substrate-implementation scope:
- New file dsl/gunbc/ci_emission.dag (NOT extension of actions.dag or ci.dag)
- EmissionTarget open enum + project_github_actions function declaration
- gunbc_ci_yml_workflow pinned-projection data binding
- NO modification to dsl/extdeps/github/actions.dag (INVARIANTS P1)
- CIWorkflowDag sourcing: Path (a) reuse CIPipeline preferred; Path (b) requires Mgr canvas

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(scope): fix ci_yml gate semantic — hand-authority dissolution, not file deletion

Per briansrls BLOCKING #PR2744 inline review 2026-05-12T06:58:55Z at line 32:
"ci_yml_dissolved requires .github/workflows/ci.yml absent from the repo, which
contradicts the same PR's YamlStatic and thin-shim targets that still need a
generated GitHub Actions workflow file; P5 and Pure Bootstrap require deleting
hand-maintenance, not deleting the executable artifact."

Finding verified — the previous gate framing ("file absent") was structurally
inconsistent with the same scope's YamlStatic/BinaryShim/PythonShim emission
strategies, all of which require some .github/workflows/ci.yml artifact
(full-emit or thin-shim) for GH Actions trigger discovery.

Fixes:
- §1 gate `ci_yml_deleted` → `ci_yml_hand_authority_dissolved`; pass condition
  reframed: file is either (a) absent, (b) committed-emission-artifact with
  regression-guard, or (c) thin-shim entry-point; NEVER hand-edited
- §0 "Hand-authored ci.yml DELETED" → "Hand-authored ci.yml AUTHORITY DISSOLVED"
- §3 Slice 8 description updated: "ci.yml hand-authority dissolution" (NOT
  "ci.yml deletion") + 6 NEW gates (was 4 NEW; pre-(c-refined) cascade count)
- §5 timeline + §7 routing references updated to "hand-authority dissolution"
- §9 aggregator depends_on list updated with renamed gate
- §1 history note updated to document 4→6 NEW + briansrls BLOCKING fix chain

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-WAD WI-2 — propagate briansrls BLOCKING substrate-fidelity concerns to Slice 4-5 canvas

briansrls posted 4 BLOCKING inline reviews on PR #2744 (2026-05-12T06:58:55Z).
Finding #1 (ci_yml gate semantic) addressed in commit 19a1d8d.

Findings #2/#3/#4 target the OLD WI-2 brief content (compose-against-carriers
scope) which was rewritten to declaration-only scope in commit 03545da. They
do NOT apply to current brief acceptance gates, but the underlying
substrate-fidelity concerns propagate to Slice 4-5 per-arm projection body
work (warm-wolf-698 canvas). Carrying forward:

- Workflow.concurrency: Concurrency? — current ci.yml uses top-level concurrency
- PullRequestActivity arm coverage — current ci.yml uses ready_for_review
- Trigger fidelity — current ci.yml has push+PR only, NO schedule fabrication
- Step body + action input completeness — MUST not SHOULD/NICE-TO-HAVE for P1
  modeling faithfulness when YamlStatic emits ci.yml-equivalent

Also updated Sequencing language to reference renamed `ci_yml_hand_authority_dissolved`
gate (consistent with §1 fix in 19a1d8d).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-WAD WI-2 — flip CIWorkflowDag sourcing to Path (b) per Substrate Mgr clarification

Per warm-wolf-698 msg_27d99080 (Substrate Mgr): Path (a) reusing CIPipeline is
INSUFFICIENT. CIPipeline { name, gates: List<CIGate> } is a FLAT gates list
without edge/dependency structure. project_github_actions consumes gate-DEPENDENCY
(which gates depend on which); flat List<CIGate> cannot serve as projection input.

Path (b) — CIWorkflowDag carrier from PR #2736 (neat-badger-30) — REQUIRED.
CIWorkflowDag { name, nodes: List<CIGateNode>, edges: List<CIGateEdge> } is the
load-bearing semantic carrier. Already canvas-tier ratified (PR #2749 §1 / §2.4 /
§7.4) AND Director-ratified (msg_4f7f536d). PR #2736 is MERGEABLE with all CI
checks SUCCESS as of 2026-05-12.

Brief updates:
- CIWorkflowDag dependency sequencing section flipped: Path (a) REJECTED (with
  reasoning), Path (b) REQUIRED with canvas + Director ratification citation
- DO/DONT section: Path (b) is now the DO; CIPipeline as input is now a DONT
- STOP-and-route language: CIWorkflowDag CARRIER CHOICE pre-ratified (no Mgr
  ratification needed for that dimension); PING covers shape (signature,
  derived-binding, module placement)
- Reference materials updated: cite PR #2749 §1/§2.4/§7.4 + PR #2736 + Director
  msg_4f7f536d; CIPipeline marked INSUFFICIENT
- Sequencing: depends on PR #2736 merge OR rebase on session/neat-badger-30
- COORDINATE list adds neat-badger-30 for input-carrier shape questions

cool-carp-720 should proceed Path (b) directly; no need to invoke
STOP-and-route-to-Mgr for the carrier choice itself.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-WAD WI-2 — exhaustive carrier inventory per codex BLOCKING #2

Per codex BLOCKING scheduled review on cc82ec4 (2026-05-12 ~07:14Z): "carrier
audit checked the hierarchy fix but not every current ci.yml top-level and
event field against attachable carriers → add a key-by-key inventory and
STOP/reroute missing carriers before WI-2."

Replaced the 4-item informal concerns list with an exhaustive top-level
inventory + representative per-job + per-step inventory. Verified 2026-05-12
against .github/workflows/ci.yml HEAD + dsl/extdeps/github/actions.dag HEAD.

5 substantive carrier gaps identified (was 2):

1. Workflow.concurrency absence (only Job.concurrency exists)
2. PullRequestActivity.ReadyForReview arm absence
3. Push.paths required-but-omitted (needs Optional)
4. WorkflowPermissions.issues/.actions required-but-omitted (needs Optional
   or PermUnset arm)
5. RunnerSpec expression-syntax gap — runs-on: ${{ vars.X || 'fallback' }} not
   representable; substrate-shape question on expression-AST modeling

Plus 3 authoring concerns: trigger fidelity NO fabrication, step body MUST,
exhaustive per-job-per-step inventory at Slice 4 canvas authoring time.

The 5 carrier gaps need pre-Slice-4 substrate-prereq PRs (extdeps-fidelity
extensions; gap #5 is canvas-tier substrate-shape decision). Concerns 6/7/8
are Slice 4 brief acceptance discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-WAD WI-2 — fix canvas PR citation (PR #2746 vs PR #2749 author attribution)

PR #2746 (head session/still-heron-763) is the still-heron-763 WI-1 emitter-dispatch
canvas (docs/design-ci-workflow-emitter-dispatch.md).

PR #2749 (head session/warm-wolf-698-substrate-shape-canvas) is warm-wolf-698's
adjacent substrate-shape comparison canvas where (c-refined) self-correction at §7
lives.

Prior brief mis-attributed PR #2749 to still-heron-763. Both PRs are part of the
canvas-tier authority chain but distinct authors + distinct artifacts.

Updates:
- Reference materials: cite PR #2746 (still-heron-763 emitter-dispatch canvas)
  separately from PR #2749 (warm-wolf-698 substrate-shape comparison canvas)
- COORDINATE line: still-heron-763 sibling = PR #2746, NOT #2749

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(scope): cursor BLOCKING fix — scope doc / brief single-authority + §2 (c-refined) lock

Per cursor BLOCKING review on 19a1d8d (2026-05-12T07:16:48Z) — 3 findings:

Finding #1 (single-authority WI-2 description scope-vs-brief divergence):
ADDRESSED. Scope doc §0/§4/§6/§8 all said "extend dsl/gunbc/ci.dag" while
brief said "new file dsl/gunbc/ci_emission.dag" — two workers reading parent
vs brief would ship incompatible artifacts (INVARIANTS P2). Fixed:
- §0 framing #1: "extend ci.dag" → "new ci_emission.dag projection-substrate"
- §4 dependency graph: WI-2 ci.dag extend → WI-2 ci_emission.dag substrate + PR #2736 CIWorkflowDag dep
- §4 parallelizable: WI-2 description updated
- §6 WI-2: full rewrite to declaration-only substrate scaffold; DOES-NOT-EXTEND callouts
- §8 references: ci.dag stays untouched; ci_emission.dag is NEW; PR #2736 input source

Finding #2 (brief still says Slice 8 deletes):
CHECKED — grep finds no "deletes" references in current brief. Was real on
older commit; subsequent cascade fixes removed. No-op.

Finding #3 (§2/§3 stale (a)-shape language while §1 locks (c-refined)):
ADDRESSED. §2 fully rewritten:
- Title: "(c-refined) substrate-shape LOCKED 2026-05-12 per PR #2749 §7"
- New section: invocation-time parameter to projection function; NOT field on carrier
- (a) Field on Workflow: RETRACTED with citation (msg_b4151f45 + codex BLOCKING #9970)
- (b) Field on CIPipeline: SUPERSEDED with reasoning (flat without edge structure per warm-wolf-698 msg_27d99080)
- (c) Wrapper node: SUPERSEDED by (c-refined) projection function
- Emitter dispatch: now describes consuming pinned-projection invocation
- Open expression-substrate question DEFERRED to PR #2751 (warm-wolf-698 canvas)
- §3 Slice 4 description: NOT "EmissionTarget field landing" — explicit NOTE

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): codex BLOCKING fix — WI-1 brief stale (a)-shape framing removed

Per codex BLOCKING on PR #2744 (2026-05-12T07:49:06Z review #10005): WI-1 brief
still had OLD (a)-shape framing that conflicts with the ratified (c-refined)
substrate-shape and the sibling WI-2 brief's NEW-file scope.

Stale framings codex flagged:
- Line 16: "Where emission_target is carried — OPEN QUESTION" presenting
  Workflow / CIPipeline / wrapper as open options (RETRACTED per Director
  msg_b4151f45 + codex BLOCKING #9970)
- Line 23: "emit ci.yml from extended dsl/gunbc/ci.dag" — but WI-2 explicitly
  does NOT extend dsl/gunbc/ci.dag (per (c-refined) shape; NEW file
  dsl/gunbc/ci_emission.dag is the projection-function substrate)
- Line 47: "EmissionTarget placement explicitly evaluated" as acceptance gate
  (placement is LOCKED, not evaluated)
- Line 66: "WI-2 extending dsl/gunbc/ci.dag" — wrong; WI-2 is new file

Fix: full brief rewrite. New structure:
- Substrate-shape ratification anchor section: states (c-refined) LOCKED;
  documents (a)/(b)/(c) RETRACTED/SUPERSEDED with citations
- Scope section: per-target emission semantics (the actual canvas surface)
  with explicit "this brief does NOT reopen the placement question"
- Reference materials: PR #2749 + PR #2736 + PR #2751 (Expression substrate)
  as upstream ratification anchors
- Acceptance gates: "Substrate-shape placement is NOT re-evaluated"
  explicitly + InlineGunbc as DESIGN-ONLY future target per PR #2746 §5.4
- STOP / PING: re-evaluation of (c-refined) requires Director re-ratification
- COORDINATE list: WI-2 sibling brief + correctly framed as projection-substrate

Brief is now coherent with:
- §1 gates per scope doc (`emission_target_open_enum_landed`,
  `project_github_actions_landed`, etc.)
- §2 (c-refined) LOCKED architectural shape
- §6 WI-2 description (NEW file dsl/gunbc/ci_emission.dag)
- WI-2 brief NEW-file framing
- PR #2746 self-correction to (c-refined) shape
- PR #2749 §7 ratification anchor
- PR #2751 Expression substrate ratification

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(scope+briefs): openai-pro BLOCKING fix — InlineGunbc DESIGN-ONLY + scope-doc stale field language

Per openai-pro BLOCKING REQUEST_CHANGES on PR #2744 (2026-05-12T07:55:34Z, db103a5f) — 2 contradiction classes:

1. **LAYER MODEL + LOCKED DESIGN** finding: scope doc §0 line 4 (Authority) +
   line 18 (framing #3) still said "modeled toggle field" / "Placement of the
   field is an open canvas question" — CONTRADICTS the locked (c-refined)
   shape at §2.

   Fix:
   - Line 4: "modeled toggle field" → "modeled data (open enum, invocation-time
     projection parameter)"; cite PR #2749 §7 ratification; reference §2 for
     (a)/(b)/(c) RETRACTED/SUPERSEDED treatment
   - Line 18: "same ci.dag emits multiple target shapes; choice is a modeled
     field; Field placement OPEN" → "same CIWorkflowDag projects through
     project_github_actions(ci_workflow_dag, target); EmissionTarget is
     invocation-time projection parameter, NOT carrier-time field; Substrate-
     shape LOCKED per (c-refined)"

2. **INVARIANTS + TRACKED DEBT** finding: WI-2 brief lines 23 + 92 instruct
   the worker to land InlineGunbc as initial enum arm + acceptance gate, WHILE
   WI-1 brief explicitly says InlineGunbc is DESIGN-ONLY with "no enum variant
   or emitter arm lands until real runtime consumer exists." Two authoritative
   instructions for the same substrate enum.

   Fix in WI-2 brief:
   - §Output line 23: removed InlineGunbc from initial enum; updated to 3 arms
     (YamlStatic, BinaryShim, PythonShim) with explicit DESIGN-ONLY rationale +
     cross-reference to PR #2746 §5.4 + WI-1 brief
   - §DO/DON'T line 73: "4 named arms" → "3 named arms" + DO-NOT-add-InlineGunbc
   - §Acceptance gate 2 (line 91): "4 named arms" → "3 named arms" + explicit
     "NO InlineGunbc arm" + DESIGN-ONLY note

   Fix in scope doc:
   - §1 gate row `emission_target_open_enum_landed`: "(YamlStatic | BinaryShim
     | PythonShim | InlineGunbc | ...)" → "3 initial arms (...)" + InlineGunbc-
     is-DESIGN-ONLY clarification
   - §2 type sketch: removed InlineGunbc from initial declaration with NOT-IN-
     INITIAL-ENUM comment
   - §2 emitter dispatch: "future = PythonShim / InlineGunbc" → "future =
     PythonShim" (PythonShim is initial); InlineGunbc DESIGN-ONLY explicit

Substrate enum now coherent across:
- §0 framing #3 (3 arms; InlineGunbc DESIGN-ONLY)
- §1 gate row body (3 initial arms; InlineGunbc DESIGN-ONLY)
- §2 type sketch (3 arms; InlineGunbc not in initial enum)
- §2 emitter dispatch (per-arm body description)
- WI-1 brief (DESIGN-ONLY discipline)
- WI-2 brief Output / DO-DONT / Acceptance gates
- PR #2746 canvas §5.4 (canonical DESIGN-ONLY framing)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(scope+briefs): cursor APPROVE_WITH_COMMENTS — reconcile PR #2751 ratification status + 4-vs-5 substrate-prereq framing

Per cursor APPROVE_WITH_COMMENTS on PR #2744 (2026-05-12T08:03:12Z, review #10018) — 2 internal-consistency findings:

Finding #1 (PR #2751 ratification status divergence): scope doc §2 line 102
said "Director ratification pending" while WI-1 brief said "Director-ratified
per msg_168005e1." Same PR cannot be both pending and ratified.

Fix: scope doc §2 line 102 updated to "Director-ratified at msg_168005e1
2026-05-12" — aligns with WI-1 brief authority chain. The ratification
happened during this cascade (relayed by Director msg_168005e1) AFTER initial
scope-doc authoring.

Finding #2 (4 vs 5 substrate-prereq framing): WI-1 said "4 small
substrate-prereq PRs already tracked" with STOP-if-more language; WI-2 listed
5 substantive carrier gaps including RunnerSpec/expression-syntax as 5th.
Workers following WI-1 could under-scope or hit STOP/false confidence
relative to WI-2 inventory.

Fix in WI-1 brief:
- §6 Carrier reuse audit: "4 small substrate-prereq PRs are tracked" → "5
  carrier gaps total: 4 small extdeps-fidelity substrate-prereq PRs PLUS 1
  substrate-shape canvas + Expression carrier" with explicit framing that
  the 5th gap is canvas-tier (PR #2751-handled), not Slice 4 extdeps-fidelity
- STOP criterion line 72: "beyond the 4 small substrate-prereq PRs" →
  "beyond the 5 already-tracked gaps (4 small substrate-prereq PRs + 1
  Expression carrier via PR #2751 canvas)"

Both briefs now coherent on the 5-gap inventory; clear distinction between
class (4 extdeps-fidelity, 1 substrate-shape canvas-tier). cursor's
P2/single-authority concern resolved.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): WI-2 brief — close CIPipeline parallel-authority ambiguity at §3 line 45 (codex BLOCKING #10028 on PR #2744)

§3 pinned-binding source line said "CIPipeline value or CIWorkflowDag
carrier" — that "or" reintroduces the same parallel-authority shape the
brief's §CIWorkflowDag-dependency-sequencing immediately rejects (Path (a)
INSUFFICIENT per warm-wolf-698 msg_27d99080: flat gates list without
edge/dependency structure cannot serve as projection input).

Tighten to single authority: `CIWorkflowDag` carrier (PR #2736) is THE
projection input; `CIPipeline` is explicitly NOT a valid source.

INVARIANTS P2 (single-authority) + modeling-discipline Practice 5
satisfied — no parallel-source ambiguity remains in worker-facing text.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(scope+briefs): T-WAD — reframe Slice 4 byte-equivalence claim (briansrls BLOCKING on PR #2744 2026-05-12T08:27:21Z)

§3 Slice 4 description + WI-1 brief §Scope.1 both said the projection
emits "Workflow value byte-equivalent to current .github/workflows/ci.yml
content". That framing conflicts with Workflow being a semantic platform
carrier — current ci.yml carries comments / blank-line whitespace / key
ordering quirks that aren't in the semantic model. Per P1/P2:
- silent loss: emission drops comments → emitted YAML ≠ current ci.yml
  (not byte-equivalent, falsifies the claim)
- second byte authority: parallel model captures formatting →
  P1 violation (CI-semantic fact lives outside the canonical carrier)

Reframe to two distinct correctness conditions:

1. External semantic-equivalence (one-time, migration-axis): emitted
   YAML is semantically equivalent to current ci.yml when consumed by
   GitHub Actions (same triggers, jobs, steps, runners, conditions,
   permissions, matrix structure). Non-semantic facts in pre-migration
   ci.yml are DISCARDED — they are not load-bearing CI logic.

2. Internal byte-identity (regression-axis): committed artifact is
   byte-identical to FRESH projection output (regression-guard gate
   already in §1 row ci_yml_hand_authority_dissolved option (b) —
   correctly framed there).

Discriminator restored: byte-identity is INTERNAL to the substrate
(projection-output ↔ committed-artifact), not EXTERNAL (substrate-output
↔ legacy hand-authored content).

Load-bearing comments in current ci.yml (workaround explanations,
dissolution-trigger pointers) must migrate into substrate as modeled
facts (structured Notes on the carrier OR inlined documentation in
dsl/gunbc/ci_emission.dag) — they MUST NOT become parallel byte-authority
alongside the semantic carrier.

Cascade per feedback_dissolution_authority_not_file_presence: same
conflation pattern appeared in BOTH the scope-doc §3 line 114 AND the
WI-1 brief §Scope.1 line 29; both reframed in lockstep.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): WI-2 brief — defer pinned-binding to Slice 4 + add Practice 4 receipt gate (briansrls 2x BLOCKING on PR #2744)

Two BLOCKING inline reviews from briansrls at 2026-05-12T08:30:15Z on
current head dd29221:

c#3224878308 (line 30 anchor, §3 pinned-binding instructions):
> "The pinned-binding instructions still allow sourcing
>  ci_workflow_dag from CIPipeline, contradicting the Path (b)
>  CIWorkflowDag authority and reopening the P2 single-authority
>  boundary the brief later locks."

Even after the earlier b2bc281 fix locked CIPipeline OUT as a valid
source, the §3 instructions still required the worker to write the
gunbc_ci_yml_workflow binding — but there is no canonical CIWorkflowDag
instance in main yet (PR #2736 introduces the carrier type, not an
instance). The worker would have to either:
  (a) invent a placeholder CIWorkflowDag value inline in
      ci_emission.dag → parallel authority alongside the eventual
      Slice 4 canonical instance (P2 violation)
  (b) build CIWorkflowDag from CIPipeline via inline conversion →
      reopens Path (a) authority despite explicit rejection (P2)
  (c) leave the binding as a non-compiling forward-reference

Fix: defer the pinned-projection binding to Slice 4. Slice 4 authors
the canonical CIWorkflowDag instance AND the pinned-projection binding
together; WI-2 scope shrinks to (1) EmissionTarget enum + receipt and
(2) projection function signature. P2 single-authority restored
because the only instance authority is the canonical Slice 4 source.

c#3224878313 (line 64 anchor, Acceptance gates section):
> "The WI-2 acceptance gate for the new substrate EmissionTarget sum
>  type omits the required 🟢/🟡/🔴 coproduct-dissolution
>  classification, so a worker could satisfy the brief while landing
>  [a parallel-taxonomy enum]."

WI-1 brief (PR #2746 merged 08:29:09Z) carries Practice 4 receipt
discipline for EmissionTarget at lines 115-141; WI-2 brief inherited
the substrate-shape without inheriting the receipt requirement,
creating a discipline asymmetry. A worker satisfying WI-2 could land
EmissionTarget without the receipt, and the substrate would carry
the same coproduct-dissolution debt the WI-1 canvas explicitly closes.

Fix: add acceptance gate 3 requiring Practice 4 receipt (🟡 YELLOW
classification + named dissolution trigger + coordinate-dissolution
sketch) co-equal with the enum declaration itself. Receipt is part
of substrate authoring discipline per modeling-discipline.md
Practice 4 + feedback_coproduct_dissolution, not optional documentation.

Cascade changes:
- §3 reworked to defer binding (with full P2 rationale)
- Acceptance gates renumbered (4 → 11; new gate 3 = Practice 4 receipt,
  new gate 5 = no pinned-binding-in-WI-2)
- DO list: removed pinned-binding instruction; added receipt-authoring
  DO
- DON'T list: 3 new DON'Ts (no binding-in-WI-2; no placeholder
  CIWorkflowDag; no enum-without-receipt)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(scope+briefs): T-WAD — EmissionTarget → WorkflowRuntime rename (name collision with SELF_HOSTING.md:609; warm-wolf-698 PR #2749 commit 575eb7e cascade)

warm-wolf-698 surfaced a DECISIVE name-collision finding at PR #2749:666
/ :672 (briansrls operator BLOCKING 2026-05-12T09:26:49Z): the canvas
EmissionTarget sum-type collides with the canonical Shape-A carrier
declared at `src/v3/SELF_HOSTING.md:609`:

  type EmissionTarget {
    language: LanguageSpec       // what's valid (required)
    rendering: RenderingSpec?    // how to format (optional)
  }

This is the SELF_HOSTING.md emitter-composition authority used across
the v3 emitter system (LanguageSpec + RenderingSpec? composition). The
PR #2749 canvas's sum-type EmissionTarget = YamlStatic | BinaryShim |
PythonShim was a literal name collision — INVARIANTS P2 violation.

warm-wolf-698 pushed rename commit 575eb7e to PR #2749:
EmissionTarget → WorkflowRuntime (48 occurrences). Per
feedback_pre_compaction_framings_self_supersede: Director ratification
msg_4f7f536d at sum-type-name level is superseded by post-ratification
name-collision discovery; all OTHER ratified elements stand (variant
names YamlStatic|BinaryShim|PythonShim, 22-site migration scope per
§5.5 expansion, 🟡 YELLOW Practice 4 receipt, projection function
signature shape, gunbc-namespace placement, dissolution trigger).

This commit cascades the rename through PR #2744 branch:

1. docs/r3-t-workflow-as-data-full-r3-close-scope.md (scope doc):
   - §0/§1 framing references (emission target / EmissionTarget)
   - §1 gate row `emission_target_open_enum_landed` →
     `workflow_runtime_open_enum_landed`
   - §1 row `project_github_actions_landed` description
   - §2 Architectural shape — all references
   - §2 added rename-rationale paragraph citing SELF_HOSTING.md:609
     authority + warm-wolf-698 PR #2749 commit + feedback memory
   - §3 Slice 4 description
   - §6 WI-1/WI-2 brief references

2. docs/briefs/r3-t-wad-full-r3-emitter-dispatch-canvas-worker.md
   (WI-1 brief — already referenced by PR #2746 merged canvas):
   - Practice 4 receipt + dissolution trigger
   - YamlStatic/BinaryShim/PythonShim arm descriptions
   - Acceptance gate references

3. docs/briefs/r3-t-wad-full-r3-cidag-scaffold-worker.md (WI-2 brief):
   - §1 enum declaration
   - §2 projection function signature
   - Acceptance gate 3 Practice 4 receipt
   - DO/DON'T list references

Sister PR cascade (separate commit on docs/r3-program-plan-t-wad-ledger-sync):
- r3-program-plan.md §1.8 row #99 gate-ID rename
- r3-structure.md §Acceptance T-WAD bullet gate-ID rename

Pending post-merge follow-on PR: docs/design-ci-workflow-emitter-dispatch.md
(already on main via merged PR #2746) needs same rename cascade — either
focused rename-only PR or Substrate Mgr lane absorption.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): WI-2 brief — fix closure-predicate vs §3 inconsistency on pinned-projection binding (briansrls BLOCKING on PR #2744 2026-05-12T09:44:22Z)

briansrls inline BLOCKING at line 5 (closure predicate):

  "The closure predicate still requires WI-2 to land
   gunbc_ci_yml_workflow even though the same brief defers that
   binding to Slice 4 until the canonical CIWorkflowDag value exists,
   reopening the P2 single-authority failure the deferral is meant
   to prevent."

The earlier f830b98 fix correctly deferred the pinned-projection
binding to Slice 4 in §3 + acceptance gate 5 + DO/DON'T list — but
the closure-predicate framing at line 5 was not updated in lockstep
and still listed the binding as a WI-2 deliverable. Same P2
single-authority drift the §3 deferral was meant to prevent.

Fix: update the closure predicate to:
- Include WorkflowRuntime enum + Practice 4 receipt + projection
  function signature (the WI-2 actual deliverables per acceptance
  gates 2/3/4)
- Explicitly note the pinned-binding deferral with cross-ref to §3 +
  acceptance gate 5
- Cite the earlier briansrls BLOCKING c#3224878308 fix in commit
  f830b98 as the authority for the deferral

Closure predicate now reads consistent with the rest of the brief.
The DO/DON'T list (already updated in f830b98) reinforces:
"Do NOT land the gunbc_ci_yml_workflow pinned-projection data binding
in this PR — DEFERRED to Slice 4."

Per feedback_dissolution_authority_not_file_presence cascade
discipline: when changing the scope-of-deliverables semantic, grep
ALL load-bearing framing sites — closure predicate at the top of the
brief is just as load-bearing as the body sections.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(scope): T-WAD — propagate pinned-binding deferral to scope-doc summaries + dependency graph (codex BLOCKING on PR #2744 commit f830b98)

codex BLOCKING review #10090 on commit f830b98 surfaced cascade gap:

  "Pinned-binding deferral was added to the detailed WI-2 scope but
   not propagated to the brief/scope-doc output summaries and
   dependency graph → update all WI-2 output/closure/cross-reference
   lines to say only WorkflowRuntime plus project_github_actions
   land in WI-2, with gunbc_ci_yml_workflow deferred to Slice 4."

The earlier commits f830b98 (WI-2 brief acceptance gate 5 deferral)
+ 011ddbc (WI-2 brief closure predicate) correctly deferred the
binding in the WI-2 BRIEF, but the SCOPE DOC carried multiple stale
claims that WI-2 lands the pinned binding. Same P2 single-authority
drift class.

Audit: grep -n "gunbc_ci_yml_workflow\|WI-2 lands\|WI-2 creates"
docs/r3-t-workflow-as-data-full-r3-close-scope.md surfaced 4 sites:

1. Line 60 (code block): "// In dsl/gunbc/ci_emission.dag (NEW file,
   WI-2 lands it):" with the gunbc_ci_yml_workflow binding inside the
   code block. Fix: split the code block into (a) "WI-2 lands the
   signature" + (b) "Invocation pin DEFERRED to Slice 4" with the
   binding shown as a comment-block forward-reference. Cite WI-2
   brief §3 + acceptance gate 5 as authority.

2. Line 149 (dependency graph parallelizable list): "WI-2 new file
   ... declares WorkflowRuntime open enum + project_github_actions
   function signature + gunbc_ci_yml_workflow pinned-projection".
   Fix: add Practice 4 receipt; mark gunbc_ci_yml_workflow as
   DEFERRED to Slice 4 with P2 rationale.

3. Line 173 (§6 WI-2 Output description): "Output: NEW file ...
   declaring WorkflowRuntime open enum + project_github_actions
   function signature + gunbc_ci_yml_workflow pinned-projection data
   binding". Fix: add Practice 4 receipt; mark binding as DEFERRED.

4. Line 206 (References list): "dsl/gunbc/ci_emission.dag — NEW
   file WI-2 creates (projection-function substrate; WorkflowRuntime
   enum + project_github_actions signature + pinned-projection
   binding)". Fix: add Practice 4 receipt; mark binding DEFERRED.

All 4 sites now consistent with WI-2 brief §3 + acceptance gate 5 +
DO/DON'T list + closure predicate (f830b98 + 011ddbc). Single
P2-clean authority surface for the WI-2 scope across both the brief
AND the scope doc.

Lesson cascaded into discipline: when changing scope-of-deliverables
semantic in ONE doc (the brief), grep ALL doc-of-record framing
sites (brief + scope-doc) for the same claim. Closure-predicate
fix in 011ddbc caught one cascade site; codex caught the
scope-doc-side cascade gap that PM missed. Future PM-side check:
after any §3 / acceptance-gate change in a worker brief, audit the
parent scope doc for matching cascade.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(scope+briefs): T-WAD — demote PythonShim to DESIGN-ONLY (briansrls BLOCKING on PR #2744 2026-05-12T10:46:59Z)

Sibling WI-1 brief marked PythonShim "Future; sketch only" (no concrete Slice consumer) but WI-2 brief listed it in the initial 3-arm enum — INVARIANTS P5 violation (declared substrate without consumer-paired slice). Fix: defer PythonShim alongside InlineGunbc; initial enum becomes 2 arms (YamlStatic, BinaryShim).

Sites updated:
- WI-2 brief line 20-26 (enum block + initial-set claim), line 76 (DO list), line 97 (acceptance gate 2)
- WI-1 brief line 31 (PythonShim DESIGN-ONLY treatment), line 61-62 (acceptance gates 2+3)
- Scope doc line 18 (WorkflowRuntime toggle text), line 40 (workflow_runtime_open_enum_landed gate description), line 51-52 (code block + comments), line 104 (per-arm projection bodies)

Symmetric DESIGN-ONLY treatment with InlineGunbc per Pure Bootstrap discipline: both land via separate substrate-prereq PRs paired with their concrete runtime consumers.

* docs(briefs): WI-2 brief — fix Practice 4 dissolution sketch admits-impossible-states (briansrls BLOCKING on PR #2744 line 101 2026-05-12T10:46:59Z)

Acceptance gate 3 said "the eventual factoring is `EmissionArtifactShape × ShimRunnerKind`" — but the Cartesian product admits impossible states like `(StaticYaml, CompiledBinary)` (you can't have StaticYaml WITH a runner; Static has no runner). Per INVARIANTS P2 illegal-states-unrepresentable discipline.

WI-1 canvas §3 in main already uses the structurally correct factoring (sum-of-tagged-coordinates, not product):

```
type EmissionTarget = Static(EmissionArtifactShape) | Shim { runner: ShimRunnerKind }
```

Fix: update WI-2 brief acceptance gate 3 to cite the canvas factoring correctly. Receipt classification language also updated to note coordinates are NOT independent dimensions.

* docs(scope): T-WAD — remove "absent" pass option from ci_yml_hand_authority_dissolved gate (openai-pro REQUEST_CHANGES on PR #2744 2026-05-12T10:51:06Z)

Gate description at line 39 allowed "(a) absent (some workflow runtimes may not require a .github/workflows/ artifact)" but line 125 explicitly says "NOT file-deletion ... all require some .github/workflows/ci.yml artifact for GH Actions trigger discovery". Contradiction would let a worker satisfy the written gate by deleting the file while failing the corrected semantic intent.

Fix: remove "absent" option from gate (both line 17 §0 framing + line 39 gate description). Initial enum (YamlStatic, BinaryShim) both REQUIRE the artifact. The "absent" option is structurally impossible — only conceivable for future DESIGN-ONLY runtimes (e.g., InlineGunbc) that don't target GH Actions, which would extend the gate at land-time via substrate-prereq PR.

Also harmonized line 125 (Slice 8 note) to remove PythonShim mention (PythonShim demoted to DESIGN-ONLY in prior commit 338a83f).

* docs(scope): T-WAD — clarify rename-paragraph variant-names listing per PythonShim DESIGN-ONLY status (openai-pro APPROVE_WITH_COMMENTS on PR #2744 2026-05-12T10:58Z)

Line 34 (rename-context paragraph) listed "All OTHER ratified elements stand: variant names (YamlStatic | BinaryShim | PythonShim)" — but PythonShim is now DESIGN-ONLY per commit 338a83f (initial enum is 2 arms only). Even though the phrase is historical-context (rename-time ratified names), openai-pro flagged it as load-bearing enough to confuse downstream workers who scan the rename paragraph and might infer PythonShim is in the initial enum.

Fix: clarify "initial-enum variant names (YamlStatic | BinaryShim); PythonShim is a reserved DESIGN-ONLY future name not in initial enum per INVARIANTS P5 — see §1 gate workflow_runtime_open_enum_landed".

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
…§7 staging (substrate prerequisite + BinaryShim consumer/runner) — swift-wren-365 msg_29f68109

Earlier draft compressed both layers into one PR. swift-wren-365 surfaced (correctly) that PR #2798 in-flight is Layer 1 substrate (closure+topo over CIWorkflowDag + CiWorkflowDiff) — Layer 2 (BinaryShim consumer of PR #2713 lens output + TestClaim D(t)/Δ(t) mapping + canvas §5 path-regex removal) is a follow-on PR depending on Slice 5 BinaryShim hook per canvas §6-§7.

§1 reframed as two-layer decomposition with explicit scope boundaries. Phase A-C explicitly scoped to Layer 2. Layer 1 in-flight under PR #2798 not in this brief's scope.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
…zed with §1 canvas-vs-PR-#2766-harness split — cursor APPROVE 10477 exploratory note

§4 PR body framing now distinguishes three authority types: canvas (BinaryShim consumption + selection algorithm + path-regex removal) + upstream lens (PR #2713 / design-affected-set-lens.md) + harness/ratchet (PR #2766). §6 reference list expanded similarly. Removes the residual 'PR #2766 substrate authority' phrasing that conflicted with §1's three-source split.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
…hain correction (codex BLOCKING on merged PR #2782) (#2801)

* docs(briefs): S6 brief fix-forward — authority chain corrected per codex BLOCKING review on PR #2782 sha b28cf88

Earlier brief mis-cited high-level T-WAD substrate-shape framing; codex caught that the actual implementation authority for affected-set selection is:
- PR #2713 (upstream affected-set lens substrate; merged) per docs/design-affected-set-lens.md §2
- docs/design-t-wad-slice-7-binary-shim-affected-set-selection-canvas.md in main (§1 BinaryShim consumption / §3 fail-closed / §4 selection algorithm / §5 path-regex removal invariant)
- PR #2766 harness contract + Layer 2 path-regex inventory ratchet

§0 + §1 rewritten to encode the correct authority chain, canvas §4 algorithm verbatim, and canvas §5 path-regex removal invariant. STOP conditions tightened to the actual fail-closed surfaces (PR #2713 serialization form, path-regex inventory drift).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S6 brief — surface 2-layer decomposition per canvas §6-§7 staging (substrate prerequisite + BinaryShim consumer/runner) — swift-wren-365 msg_29f68109

Earlier draft compressed both layers into one PR. swift-wren-365 surfaced (correctly) that PR #2798 in-flight is Layer 1 substrate (closure+topo over CIWorkflowDag + CiWorkflowDiff) — Layer 2 (BinaryShim consumer of PR #2713 lens output + TestClaim D(t)/Δ(t) mapping + canvas §5 path-regex removal) is a follow-on PR depending on Slice 5 BinaryShim hook per canvas §6-§7.

§1 reframed as two-layer decomposition with explicit scope boundaries. Phase A-C explicitly scoped to Layer 2. Layer 1 in-flight under PR #2798 not in this brief's scope.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S6 brief §4 PR-body framing + §6 reference list harmonized with §1 canvas-vs-PR-#2766-harness split — cursor APPROVE 10477 exploratory note

§4 PR body framing now distinguishes three authority types: canvas (BinaryShim consumption + selection algorithm + path-regex removal) + upstream lens (PR #2713 / design-affected-set-lens.md) + harness/ratchet (PR #2766). §6 reference list expanded similarly. Removes the residual 'PR #2766 substrate authority' phrasing that conflicted with §1's three-source split.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
* docs(briefs): S6 brief fix-forward — authority chain corrected per codex BLOCKING review on PR #2782 sha b28cf88

Earlier brief mis-cited high-level T-WAD substrate-shape framing; codex caught that the actual implementation authority for affected-set selection is:
- PR #2713 (upstream affected-set lens substrate; merged) per docs/design-affected-set-lens.md §2
- docs/design-t-wad-slice-7-binary-shim-affected-set-selection-canvas.md in main (§1 BinaryShim consumption / §3 fail-closed / §4 selection algorithm / §5 path-regex removal invariant)
- PR #2766 harness contract + Layer 2 path-regex inventory ratchet

§0 + §1 rewritten to encode the correct authority chain, canvas §4 algorithm verbatim, and canvas §5 path-regex removal invariant. STOP conditions tightened to the actual fail-closed surfaces (PR #2713 serialization form, path-regex inventory drift).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S6 brief — surface 2-layer decomposition per canvas §6-§7 staging (substrate prerequisite + BinaryShim consumer/runner) — swift-wren-365 msg_29f68109

Earlier draft compressed both layers into one PR. swift-wren-365 surfaced (correctly) that PR #2798 in-flight is Layer 1 substrate (closure+topo over CIWorkflowDag + CiWorkflowDiff) — Layer 2 (BinaryShim consumer of PR #2713 lens output + TestClaim D(t)/Δ(t) mapping + canvas §5 path-regex removal) is a follow-on PR depending on Slice 5 BinaryShim hook per canvas §6-§7.

§1 reframed as two-layer decomposition with explicit scope boundaries. Phase A-C explicitly scoped to Layer 2. Layer 1 in-flight under PR #2798 not in this brief's scope.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S6 brief §4 PR-body framing + §6 reference list harmonized with §1 canvas-vs-PR-#2766-harness split — cursor APPROVE 10477 exploratory note

§4 PR body framing now distinguishes three authority types: canvas (BinaryShim consumption + selection algorithm + path-regex removal) + upstream lens (PR #2713 / design-affected-set-lens.md) + harness/ratchet (PR #2766). §6 reference list expanded similarly. Removes the residual 'PR #2766 substrate authority' phrasing that conflicted with §1's three-source split.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #62 file-ingestion substrate-shape canvas

Surfaces the substrate-shape question for §1.8 row #62
substrate_gap_file_ingestion_closed before brief authoring.

bright-otter-731 was auto-spawned on this gate without an
authored brief and surfaced a clean audit (no include_str! at
HEAD in dsl/; PR #2819 read_utf8_file candidate shape held in
draft). §4.3 line 505 frames closure as workflow_substrate
extension to file-attachment (Candidate B), but PR #2819 implements
compile-time UTF-8 read (Candidate A) — parallel-authority risk.

This canvas frames the candidate shapes (A/B/C/d) for Director-or-
Substrate-Mgr-tier ratification before brief authoring proceeds.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #62 FileAttachment carrier-internals sub-canvas

Director ratified Candidate (b) on PR #2820 — workflow-substrate
FileAttachment carrier extending #53 — per PM msg_52c4a707. This
sub-canvas surfaces carrier internals (type def + fields + workflow
coupling + Practice 4 + lazy-vs-eager) for next-tier ratification
per recursive feedback_substrate_shape_belongs_in_mgr_canvas.

Three candidate shapes (B-1 minimal / B-2 path-keyed / B-3 anchor+entry
pair) anchored against gate #55 WorkflowObservationAnchor precedent at
src/v3/std/timing_lens.dag:98 (already CONSUMER_LANDED).

Director anti-patterns encoded for worker review enforcement.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #62 FileAttachment worker brief (Refined-B-1 ratified)

Director ratified Refined-B-1 carrier shape with full §8 Q1-Q6
dispositions + 7 anti-patterns per PM msg_bc8c23f6 (relaying Director
msg_61e302c6). Worker brief authored with:

- Exact 5-field carrier (subject_node + content_digest + producer_id +
  workflow_run_id + attached_at_ns) — strict 5-of-7-subset of #55
  WorkflowObservationAnchor
- Q1-Q6 dispositions encoded verbatim for reviewer enforcement
- 7 anti-patterns receipt-of-compliance requirement
- Phase A (carrier) / Phase B (ratchet test) / Phase C (existence-proof
  use case) / Phase D (ledger update) staging
- 5 STOP conditions including consumer-evidence-blob-store gap
- Workflow blob-store substrate flagged as Wave-2 sub-canvas-2 trigger
  (forward-looking, NOT blocking this brief)

Brief is DISPATCH-READY. PR #2819 stays held as Candidate A drift
(anti-pattern #1).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
…r operator directive (Director ratification pending) (#2822)

* docs(briefs): R3 CI Layer 2 — PM pre-staged Mgr-fill template

Author the pre-staged Mgr-fill reference doc Director accepted via
msg_4623068b at 22:54Z (greenlight on PM's pre-staged-skeleton offer
from gunbc#828 c4425726922). Director will cite this file in their
forthcoming worker brief (`docs/briefs/r3-ci-layer-2-path-conditional-
gating-worker.md`) as the starting template for Verification Mgr
(clever-tern-670) inventory finalization.

Content:
- §1 affected-set lens Dimension enum reference (cite design doc §2)
- §2 slow-test inventory grouped into 9 clusters (78 entries from
  scripts/slow-test-exemptions.txt)
- §3 path-mapping skeleton table — (test_pattern, dimension,
  required_paths_regex, confidence, dissolution_note). PM partial-
  fills high-confidence rows; ~12 [Mgr-fill] placeholders left for
  rows requiring deeper substrate-lens / consumer-tracing knowledge
- §4 open questions for Mgr (multi-dim split, conservative defaults,
  pilot cluster selection — recommended Cluster B = Lane 2 Stage 2d
  symbolic cost; high-confidence single-dimension contained module)
- §5 acceptance checklist for Mgr-fill completion
- §6 STOP triggers (new substrate carrier need; dimension outside
  enum; test-output dependency = lens not bridge)
- §7 cross-refs (Layer 1 PR #2718, lens canvas PR #2713, routing
  msg_a77c7f42, memory feedback_parallel_representation_debt)

Hard constraint per feedback_parallel_representation_debt: every row
carries a dimension: field matching the lens Dimension enum so post-
dissolution skip_* flags compute structurally as
`affected_dimensions.contains(group.dimension)` — same enum,
structural source. Prevents path-mapping schema divergence from
future lens API surface.

Dissolution trigger: gate
ci_uses_provable_minimal_affected_set_selection (R3 close-blocking;
docs/design-affected-set-lens.md §5). When the lens lands, this
template + the worker output are deleted.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — dimensions is Set<Dimension>, not single primary (codex REQUEST_CHANGES fix on PR #2721)

codex REQUEST_CHANGES on PR #2721 (review #9707) caught a semantic-
contract violation: the template asserted "every entry carries exactly
one primary `dimension:`" and post-dissolution `skip_*` computation as
`affected_dimensions.contains(group.dimension)`. This conflicts with
the locked design at `docs/design-affected-set-lens.md` §2:

  affected_set(Dag_before, Dag_after) =
    ⋃ over dim in {Value, Cost, Complexity, Effect, Refinement}
      affected_set(Dag_before, Dag_after, dim)

A test that reads BOTH Cost AND Complexity (e.g., D-cluster LBP
demonstration; lane2_stage_2f composed-matches-lens) would be silently
skipped when only Complexity changes if its dimension is narrowed to
"Cost." That's `INVARIANTS.md` P2 single-authority violation against
the locked lens design.

Fixes:
- §1: rewrite from "exactly one primary dimension" to "dimensions is
  Set<Dimension> = full read-set; affectedness is union semantics"
- Header bullet: hard constraint reframed — multi-dim REQUIRED when
  consumer reads multi; post-dissolution math is `(affected ∩ row.dimensions) ≠ ∅`
- §3 table: column rename `dimension` → `dimensions`; rows updated:
  - D-cluster LBP, lens_cost_target_realization, cost_lens_consumer:
    expanded to multi-dim sets [Complexity, Cost], [Cost, Value]
  - lane2_stage_2f_dimension: [Complexity, Cost] (composed-matches-lens)
  - F-`m0_acceptance` + I-`thesis_validation_test`: full 5-dim set
    (compile-boundary + thesis-level read every dim)
  - G-`t_las_crdt_cost_basis_demo`: [Cost, Effect, Value]
  - G-`r3_free_consequences_second_batch`: [Cost, Value]
  - H-`t_ci_workflow_as_data_demo`: [Value, Cost] (DimensionReport timing)
  - All single-dim rows (A, B, Most-C, etc.): formatted as set `[Cost]`
- §4 Open question 1: rewrite to forbid narrowing, mandate ADD-when-doubt
- §5 acceptance: add dim-set-semantics + union-formula checks
- §6 STOP triggers: add "tempted to narrow set → STOP and EXPAND"

Director's Layer 2 brief at PR #2719 has the same singular-`dimension:`
shape and likely has the same finding waiting to surface; will flag to
Director after this lands.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template count + wording fixes (cursor BLOCKING #9719 on PR #2721)

cursor BLOCKING REVIEW on PR #2721 (review #9719 at dedcf69) caught
factual count discrepancies + the stale singular `dimension` echo
that openai-pro had flagged as non-blocking:

1. Cluster A banner — was "(~10)", actual sum = 1+6+2+6 = 15 → fixed to "(15)"
2. Cluster B individual-row count "6" while listing 7 names → fixed to 7;
   banner "(~6)" → "(7)"
3. emit_matrix Notes "5× emit matrix sweep" while listing 6 tests
   (3 module + 3 program) → fixed to "6× emit matrix sweep (3 module
   + 3 program)" for explicit attribution
4. Cluster D banner "(~5)", actual sum = 2+3+2+2 = 9 → fixed to "(9)"
5. Line 7 (Purpose) stale singular `(test_pattern, dimension,
   required_paths_regex)` echo → fixed to `dimensions` plural;
   converges with openai-pro APPROVE_WITH_COMMENTS observation (review
   #9714) that had been deferred to follow-up — cursor's BLOCKING
   verdict overrides the deferral

§4 Open question 5 (pilot recommendation) also corrected from
"~6 tests" to "7 tests" for Cluster B consistency.

Clusters C/E/F/G/H/I banner counts re-verified against table sums
(7/12/6/10/7/5 respectively) — all already exact, no change needed.

P1 Modeling Faithfulness restored: every cluster banner now matches
its enumerated tests-column sum.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — fix skip_<cluster> polarity (openai-pro BLOCKING #9721 on PR #2721)

openai-pro re-review on PR #2721 at sha 93080af caught a critical
boolean polarity inversion in the skip_<cluster> formula. A Mgr/worker
following the brief literally would have wired the CI gate backward,
silently skipping affected tests — TESTING.md "test selection must
not skip affected behavior" violation + Boundary Discipline violation
(boolean carrier name and contract encoded opposite meanings).

**The bug**: 4 places stated post-dissolution `skip_<cluster>` formula
as `(affected_dimensions ∩ group.dimensions) ≠ ∅` (skip when
intersection NON-empty), while the CI consumer wires
`if: skip_<cluster> != 'true'` (run when skip is NOT true). Combined:
when intersection is non-empty (= affected), skip=true → tests don't
run → affected tests silently skipped.

**The fix**: invert the formula to `(intersection = ∅)` (skip when
intersection IS empty = no affected dim that this cluster reads). The
CI gate semantics stay the same; the polarity correction is on the
post-dissolution lens mapping.

Sites corrected:
- §1 hard-constraint para (line 9): replaced "(non-empty intersection
  means run)" with an explicit Boolean polarity block defining
  `skip = (intersection = ∅)` and equivalent `run = (intersection ≠ ∅)`
- §3 path-mapping intro (was line 132, now 142): same polarity fix
  + "Equivalently: `run = (intersection ≠ ∅)`"
- §4 open-question 4 (was line 186, now 196): "skip_<cluster> becomes
  `(intersection ≠ ∅)`" → `(intersection = ∅)` with explicit
  "same polarity: skip when no affected dim" note
- §5 acceptance (was line 206, now 216): same polarity fix +
  explicit "inverting the polarity silently skips affected tests" warning

All 4 references now consistent. Polarity table:
  intersection = ∅  → skip=true  → "do not run" (NOT affected, safe to skip)
  intersection ≠ ∅  → skip=false → "run" (affected, must run)

Director's brief #2719 likely has the same polarity issue and will need
parallel fix from the same authority chain. Flagging separately.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — cluster aggregation + path-regex verification discipline (codex BLOCKING on PR #2721)

codex BLOCKING review on PR #2721 at sha 262f42d caught two
substantive gaps:

**(1) Cluster aggregation predicate missing**: §3 defined per-row
intersection check but didn't specify how multi-row clusters
aggregate to the cluster-level `skip_<cluster>` boolean. A worker
following the brief could implement disjunction (any-row-empty
= skip cluster) which would silently skip the OTHER affected rows
in the cluster when only one row is unaffected.

Fix: explicit conjunction predicate in §3 + §4 + §5 + §6:
  skip_<cluster> = ∀ row ∈ cluster : (changed_files ∩ row.regex) = ∅
Equivalently: run_<cluster> = ∃ row ∈ cluster : row affected.

**(2) Path regexes PM-authored without source-tree verification**:
PM concrete `required_paths_regex` values in §3 were manually
authored from the inventory SHA references without validation
against actual paths in the source tree. Workers might wire CI
gates against stale paths.

Fix: explicit Mgr-verification discipline in §3 + §4 + §5 + §6:
- Workers MUST validate each concrete regex against source tree
  at HEAD before CI implementation
- Unverified or unverifiable regexes → `.*` per conservative
  fail-closed default
- Confidence column treated as audit priority (low → `.*` first,
  medium → audit then decide, high → audit but likely fine)
- Validation record kept (PR description or commit message)

Both fixes preserve the locked-design polarity from earlier
revisions:
- Per-row formula stays `(intersection = ∅)` for skip semantic
- Cluster aggregation is conjunction over rows (∀)
- Run formula is the structural complement (∃ ↔ ≠ ∅)

All 4 places updated: §3 path-mapping skeleton intro + §4 mechanism
+ §5 acceptance + §6 STOP triggers. Brief now structurally
guards against:
- polarity inversion (skip = ∅, not ≠ ∅; openai-pro caught prior)
- dimension cardinality narrowing (Set<Dimension>, not single; codex
  caught prior)
- cluster aggregation by disjunction (∀, not ∃; codex caught this)
- regex authoring without source-tree validation (codex caught this)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — fix stale dsl/std/ lens-paths (codex BLOCKING inline at line 152)

codex BLOCKING inline-review at line 152 (sha 262f42d) caught
that Cluster B's regex used stale `dsl/std/lens_cost.*\.dag` +
`dsl/std/cost.*\.dag` paths while the live cost-lens authority
is at `src/v3/lenses/cost.dag`. A change to the live authority
file would NOT match the stale regex → skip_b=true → cost-lens
tests silently skipped (P3 fail-closed + P2 single-authority
violation).

**Systematic audit + fix**: stale `dsl/std/<lens>.dag` pattern
applied across many rows (PM authored assuming lens .dag lived
in dsl/std/, but the live tree has them at src/v3/lenses/):

| Row | Old (stale)                                    | New (verified)                                                 |
|-----|------------------------------------------------|----------------------------------------------------------------|
| B   | dsl/std/lens_cost.*.dag + dsl/std/cost.*.dag   | src/v3/lenses/cost(_target_realization)?.dag                   |
| C-i | dsl/std/lens_idempotency.*.dag                 | src/v3/lenses/idempotency.dag                                  |
| C-p | dsl/std/lens_provenance.*.dag                  | src/v3/lenses/(provenance\|emission_provenance).dag            |
| C-u | dsl/std/lens_unused_parameters.*.dag           | src/v3/lenses/unused_parameters.dag                            |
| E×4 | dsl/std/(complexity\|cost\|symbolic_cost).*.dag | src/v3/lenses/(complexity\|cost).dag                           |
| F-b | dsl/std/boolean_algebra.*.dag                  | dsl/std/logic.dag (boolean-algebra concepts live there)        |
| G-c | dsl/std/complexity.*.dag                       | src/v3/lenses/complexity.dag                                   |
| G-l | dsl/std/(cost\|las\|crdt).*.dag                | `.*` (Mgr-fill; T-LAS substrate-deps not PM-traced yet)        |
| H-2 | dsl/std/parse.*.dag                            | src/v3/std/parse_surface.dag + src/v3/compiler/parse_tables.dag|
| H-2c| dsl/std/parse_tables.*.dag + dsl/std/tokenize  | src/v3/compiler/parse_tables.dag + src/v3/(compiler\|std)/tokenize.dag |
| H-w | dsl/std/workflow.*.dag                         | src/v3/std/workflows.dag                                       |

Confidence column dropped from `high` to `medium` for all
post-correction rows — Mgr should still validate each path
against live source tree at HEAD before CI implementation per
the verification-discipline added at d19a1a0. dissolution_note
column carries inline "**Path correction**: ..." annotations
documenting each fix for reviewer audit.

Cross-cluster bug-class catches now mapped on this template:
1. Dimension cardinality (Set<Dimension>; dedcf69)
2. Boolean polarity (skip = ∅; 262f42d)
3. Count discrepancies + line-7 singular (93080af)
4. Cluster aggregation predicate (∀ not ∃; d19a1a0)
5. Path-regex verification discipline (d19a1a0)
6. **Stale dsl/std/ lens-paths corrected to src/v3/lenses/** (this fix)

Brief structurally validated across 6 distinct axes.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — fix regex alternation escape (openai-pro APPROVE_WITH_COMMENTS on #2721)

openai-pro APPROVE_WITH_COMMENTS on PR #2721 at sha 45fc195 caught
a non-blocking regex error: line 185 had `src/v3/(compiler\|std)/tokenize.dag`
with `\|` (markdown-cell pipe escape), which a regex engine would
interpret as the literal string `compiler|std`, NOT as alternation
between `compiler` and `std`.

Mechanism of the bug:
- Markdown tables use `|` as column separator
- To put a literal `|` IN a cell (outside backticks), you escape with `\|`
- PM authored the regex with `\|` thinking the markdown-table escape
  was needed, but the regex is INSIDE backticks (code span) which
  preserves pipe character literally
- A worker copying the regex into ci.yml would silently miss
  tokenize.dag changes (only matches literal `compiler|std/tokenize.dag`)

Fix: drop the unnecessary `\` escape; markdown code spans preserve
`|` literally. Now regex correctly reads
`src/v3/(compiler|std)/tokenize.dag` — alternation between
src/v3/compiler/tokenize.dag and src/v3/std/tokenize.dag, both of
which exist per the source tree verified at 45fc195.

Mitigation: the template's own validation discipline at §3 + §5 §6
(workers MUST validate regex against live source tree before CI
implementation) would have caught this, but per openai-pro's read
"the concrete row should still not carry a known-bad example" — fair.

Cumulative bug-class catches on this template now 7 axes hardened:
1. Dimension cardinality (Set<Dimension>; dedcf69)
2. Boolean polarity inversion (skip = ∅; 262f42d)
3. Count discrepancies + line-7 singular (93080af)
4. Cluster aggregation predicate (∀ not ∃; d19a1a0)
5. Path-regex verification discipline (d19a1a0)
6. Stale dsl/std/ lens-paths corrected (45fc195)
7. Markdown-cell-escape leaking into regex semantics (this fix)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — Dimension enum is OPEN per design §2 + THESIS user-defined dims (codex BLOCKING on PR #2721)

codex BLOCKING inline-review at line 186-ish caught that my §6 STOP
trigger hard-rejected any `dimensions:` element outside the built-in
base set `{Value, Cost, Complexity, Effect, Refinement}` — which closes
the user-extensibility surface that THESIS + docs/design-affected-set-
lens.md §2 leave intentionally open with the trailing `...`.

Verification (codex was correct):

- `docs/design-affected-set-lens.md` §2: `⋃ over dim in {value, cost,
  complexity, effect, refinement, ...}` (note ellipsis = open enum)
- `THESIS.md` "User-defined dimensions" section: 'User-declared
  dimensions extend the same structural proof surface ... the ceiling
  of what gunbc can prove is user-extensible.'

The built-in base set ≠ the full enum. My template was treating them
as equivalent, which would have rejected valid user-defined dims at
the STOP gate (INVARIANTS P1 single-authority violation against
THESIS/design + P3 fail-closed violation since rejection-instead-of-
fail-closed is the opposite of safety).

Fixes:
- **§1** Dimension enum reference: rewrote with explicit `Dimension =
  {value, cost, complexity, effect, refinement, ...}` notation + the
  trailing `...` annotated as "OPEN for user-defined" + paragraph on
  THESIS user-extensibility framing + explicit instruction to treat
  unknown dim as fail-closed (always-run), NOT reject
- **§5** acceptance criterion: updated to reference the open enum +
  fail-closed-for-unknown behavior
- **§6** STOP trigger: now reads "cannot be carried as a typed
  Dimension at all (e.g., string-as-dimension, runtime-only)" — that's
  the genuine structural failure. Encountering a NEW user-defined
  dimension is NOT a STOP; it's a row carried as fail-closed-always-run

Cumulative bug-class catches on this template now 8 axes hardened
(was 7 before this fix; ci-skip-pattern-script wasn't applicable here):
1. Dimension cardinality (Set<Dimension>; dedcf69)
2. Boolean polarity inversion (skip = ∅; 262f42d)
3. Count discrepancies + line-7 singular (93080af)
4. Cluster aggregation predicate (∀ not ∃; d19a1a0)
5. Path-regex verification discipline (d19a1a0)
6. Stale dsl/std/ lens-paths corrected (45fc195)
7. Markdown-cell-escape leaking into regex semantics (7cbf29f)
8. **Dimension enum hard-closed rejecting user-defined** (this fix) —
   THESIS + design doc §2 explicitly leave open

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — carry user-defined Timing dim explicitly (codex BLOCKING on PR #2721)

codex BLOCKING re-review at sha c61a7ed line 197 (~193 in their
relay) caught a narrowing residual after the prior open-enum fix:
the `t_ci_workflow_as_data_demo_test` row carried `[Value, Cost]`
but the test actually evaluates `DimensionReport<TimingMeasurement>`
/ `ci_modeled_timing` — a user-defined Timing dim distinct from
generic Cost.

My prior open-enum fix (c61a7ed) updated §1/§5/§6 to ALLOW user-
defined dims but I didn't fix THIS row to USE one. Per the just-
established 'carry the dim, don't narrow' framing in §6, this row
should carry `[Value, Cost, Timing]` (or just `[Value, Timing]` if
Cost is sufficiently distinct from Timing in the test).

**Why it's load-bearing**: a future timing-only delta (e.g.,
DimensionReport schema change touching only timing fields, not Cost)
would be 'affected' for this test under the lens but the prior row
narrowed Timing → Cost → if Cost.affected = empty but Timing.affected
non-empty, test would be silently skipped (TESTING.md violation +
THESIS user-defined-dims framing violation).

Fix:
- Row dimensions: `[Value, Cost]` → `[Value, Cost, Timing]`
- Row dissolution-note: explicit annotation citing
  `DimensionReport<TimingMeasurement>` + `ci_modeled_timing` user-
  defined dim + the carrying-vs-narrowing rationale
- Self-references this template's own open-enum support per §1 —
  the row is now an in-table demonstration of the open-enum framing
  (consistency between framing and example)

This also re-stress-tests cluster aggregation: cluster H aggregates
over multiple rows including this Timing-carrying row, so cluster-
level skip computation correctly fail-closes when ANY row's dim
intersects with affected_dims.

Cumulative bug-class catches on this template now 9 axes hardened:
1. Dimension cardinality (Set<Dimension>)
2. Boolean polarity inversion (skip = ∅)
3. Count discrepancies + line-7 singular
4. Cluster aggregation predicate (∀ not ∃)
5. Path-regex verification discipline
6. Stale dsl/std/ lens-paths corrected
7. Markdown-cell-escape regex
8. Dimension enum hard-closed (open per THESIS)
9. **Narrowing user-defined dim to built-in** (this fix; carry don't normalize)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — codify 3-arm regex completeness invariant (mirror Director PR #2727 worker-brief discipline)

Director's PR #2727 absorbed Brian inline + codex BLOCKING convergent
finding on post-#2719 fail-open hole: per-group regex must include
THREE arms — deps + test-source + fixture — missing any is a
P3 fail-open boundary class.

This template (PR #2721) had the same structural issue: most PM-
authored rows have arms (1) deps + (2) test-source but lack arm (3)
`tests/dag/*.dag` fixture explicitly. Per Director's canonical
worker-brief discipline (PR #2727), this mirrors the gap and adds
the 3-arm completeness invariant to align.

Updates:
- §3 path-mapping intro: explicit 3-arm completeness invariant + per-
  arm fail-open semantics + audit note that PM-authored rows in §3
  below need Mgr fixture-arm audit for tests reading from
  `tests/dag/*.dag` (e.g., `t_pb_b_1_dag_runner_test` consumes
  `tests/dag/t_pb_b_1_*.dag`)
- §5 acceptance: new checklist item — every concrete regex includes
  arms (1) + (2) + (3) where applicable; Mgr-fill rejects missing
  arms 2/3
- §6 STOP triggers: two new STOP triggers for missing test-source
  arm OR missing fixture-arm-when-applicable
- Cross-link to Director PR #2727 / #2719 for canonical framing

This codifies but does NOT retrofit existing §3 rows — that's
Mgr-fill audit work (per the §3 disclaimer + Mgr-fill discipline).
PM signals the gap; Mgr fixes per row.

Cumulative bug-class catches on this template now 10 axes:
1. Dimension cardinality (Set<Dimension>)
2. Boolean polarity inversion
3. Count discrepancies + line-7 singular
4. Cluster aggregation predicate (∀ not ∃)
5. Path-regex verification discipline
6. Stale dsl/std/ lens-paths
7. Markdown-cell-escape regex
8. Dimension enum hard-closed (open per THESIS)
9. Narrowing user-defined dim (Timing→Cost)
10. **Missing test-source/fixture arms in regex** (this fix mirroring
    Director PR #2727 worker-brief discipline)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — restore `...` ellipsis in quoted §2 union formula (cursor APPROVE_WITH_COMMENTS-level exploratory on PR #2721)

cursor APPROVE review #9858 at sha 5c227c5 noted an exploratory
inconsistency: my quoted design-doc §2 union formula at lines 48-51
enumerated only the 5 built-in dimensions without the trailing `...`
that the actual `docs/design-affected-set-lens.md` §2 has, while my
surrounding text (lines 27-33, §1 enum reference) stresses the open-
enum framing.

Fix: restore the `...` in the quoted formula + add inline annotation
'← OPEN per §2; user-defined dims extend' so Mgr-fill readers can't
misread the box as closed.

Now lines 27-33 (open-enum framing) + lines 48-51 (formula quote) +
§5 acceptance + §6 STOP triggers all consistently affirm the open-
enum framing per THESIS user-defined dimensions.

Non-blocking exploratory observation; quick fix because the cost is
trivial (1-char + comment) and the value is internal-consistency
preservation.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — add test-source arm to 4 rows violating own 3-arm invariant (codex BLOCKING on PR #2721)

codex BLOCKING REQUEST_CHANGES at sha 8f11a35 caught my OWN 3-arm
completeness invariant being violated by 4 rows that ship concrete
regex but lack test-source arm. Per the invariant I codified in §3 +
§5 + §6, every concrete regex MUST include the OWN test-source arm
under `src/v3/compiler/tests/integration/`. These rows didn't:

1. `dimension::analyze_complexity_tests::.*` — had `tests/integration/dimension.*\.rs` arm but that file doesn't exist (tests live inline as a module in `tests/integration.rs`); arm matched nothing → fail-open
2. `dimension::fail_closed_tests::.*` — NO test-source arm
3. `e7_analyze_complexity_integration::.*` — NO test-source arm
4. `lane2_stage_2f_dimension_test::.*` — NO test-source arm
5. `sg2c1_parse_tables_authority_test::.*` — NO test-source arm

Fix: add test-source arm to each row:
- For inline modules (dimension/e7/lane2_stage_2f): test lives inline
  in `src/v3/compiler/tests/integration.rs`; add that path. Broad-but-
  correct per fail-closed default (any edit to integration.rs triggers
  these tests; a finer-grained match isn't expressible via path regex
  because the modules are inline in the file).
- For sg2c1 (standalone file): add explicit
  `src/v3/compiler/tests/integration/sg2c1_parse_tables_authority_test\.rs`.

Each row's dissolution_note now carries inline annotation citing the
codex BLOCKING finding + the test-source-arm correction rationale.

**Lesson**: codifying the invariant in §3/§5/§6 doesn't retrofit
existing rows — needed to AUDIT each concrete regex against the
invariant after codification. PM did partial audit on path correctness
(dsl/std → src/v3/lenses) but didn't re-audit for test-source-arm
presence. cursor #9858 noted earlier the boxed-formula inconsistency
in §1; codex now caught the same class on §3 row content. Audit
discipline = match-the-framing-everywhere, not just-codify-the-framing.

Cumulative bug-class catches on this template now 11 axes hardened:
1. Dimension cardinality (Set<Dimension>)
2. Boolean polarity inversion
3. Count discrepancies + line-7 singular
4. Cluster aggregation predicate (∀ not ∃)
5. Path-regex verification discipline
6. Stale dsl/std/ lens-paths
7. Markdown-cell-escape regex
8. Dimension enum hard-closed (open per THESIS)
9. Narrowing user-defined dim (Timing→Cost)
10. 3-arm regex completeness invariant codified
11. **Existing rows violated own 3-arm invariant** (this fix — codification didn't retrofit)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add R3 close interrogation sheet — meta-acceptance checklist per operator directive 2026-05-13

Operator directive: come up with checklist of questions/interrogation as a sheet to check things off to close R3. Director busy — PM authoring draft for ratification.

Doc scope:
- Meta-acceptance complementary to §1.8 state-check predicates
- §1.8 verifies structural form; this sheet asks did each predicate execute at close-time, does match-target reflect semantic intent, are cross-doc ledgers internally coherent, are audit-doc ratifications all on-ledger
- §0 purpose + relationship to existing authority (§1.6 demo principle, §1.7 status, §1.8 ledger)
- §1-§12: 12 interrogation categories
  - §1 per-gate predicate execution audit
  - §2 cross-doc ledger consistency
  - §3 semantic intent verification (gotcha audit per predicate-family)
  - §4 cross-gate interaction
  - §5 standing-program ledger
  - §6 audit-doc ratification trail
  - §7 behavioral demonstration coverage
  - §8 substrate fail-closed audit
  - §9 hand-Rust ledger
  - §10 documentation coherence
  - §11 external-facing surfaces
  - §12 close ceremony
- §13 disposition tracking (NOT-CHECKED / PASSING / FAILING / NEEDS-AUDIT / N/A)
- §14 anti-patterns post-close (regression prevention)
- §15 open questions for Director ratification (Q1-Q5)

Authoring shape:
- PM-tier draft per operator directive; Director (zesty-bear-812) ratification expected before R3-close ceremony
- 5 open questions surfaced for Director disposition (Q1 mechanized vs manual predicate run, Q2 audit-doc close-window, Q3 operator sign-off form, Q4 NEEDS-AUDIT blocking semantics, Q5 reviewer-bot encoding for anti-patterns)

Out of scope:
- New gate authoring (that's §1.8 ledger work)
- DECLARED → PASSING transitions (per-gate Mgr work)
- R4 forward-looking acceptance (WISHLIST.md)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): interrogation sheet v1 — adversarial promise-vs-delivery audit per operator directive

Operator refinement directive 2026-05-13: "i want the doc to be antagonistic — we have to go over all the work that was done, acceptance criteria — what was promised, what was delivered. for example complexity — how do we know it 'works' — we actually promised to deliver complexity errors — are those working? whats an example of one — do we have a demo?"

Restructure: v0 was structural meta-checklist (did predicates run, are counts coherent). v1 is adversarial promise-vs-delivery interrogation — for every promise: cite the verbatim claim, cite the delivery, demand a concrete example, attempt a falsification probe.

New structure:
- §0 disposition vocabulary (NOT-CHECKED / PROVEN / WEAK-EVIDENCE / GAP / R4-DEFERRED / NOT-PROMISED)
- §1 dimension promises (complexity, cost, parallelism, effect_enumeration, user-defined) — verbatim promise + 4-9 probes per dim
- §2 substrate promises (PB-0, closed system, cost-of-change=1, fail-closed)
- §3 emission promises (omni-emission 5 targets, workflow-as-data, tests-as-data)
- §4 self-application promises (lens self-application, self-host fixed point)
- §5 closure-criteria promises (5 substrate-gap classes, v2 retirement, BridgeLedgerZero)
- §6 "show the correct code" promise (THESIS.md:103-105 diagnostic discipline)
- §7 cross-doc ledger coherence (structural — kept from v0)
- §8 per-gate predicate execution at close
- §9 anti-patterns post-close
- §10 close ceremony
- §11 6 open questions for Director ratification
- §12 authoring history (v0 → v1)

Probe pattern (every promise):
1. Verbatim promise + doc citation
2. "Show me the .dag program / code / test that delivers it"
3. "Show me a concrete example with input → output"
4. **Falsification probe**: what would disprove "delivered"; has it been attempted?

Example (§1.1 Complexity): show .dag program that violates complexity contract, verbatim error message, second example with different complexity class, test pinning the diagnostic, behavior when contract removed, behavior with LYING annotation, end-to-end demonstration path, run on clean checkout, falsification probe (untested complexity violation case).

R3 closes when every probe is PROVEN or R4-DEFERRED with operator acceptance. Zero GAP. Zero WEAK-EVIDENCE.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
…h A Tier 1 per Director msg_ad5e934d) + §1.2/§1.5 interrogation probe refinement (#2824)

* docs(briefs): R3 CI Layer 2 — PM pre-staged Mgr-fill template

Author the pre-staged Mgr-fill reference doc Director accepted via
msg_4623068b at 22:54Z (greenlight on PM's pre-staged-skeleton offer
from gunbc#828 c4425726922). Director will cite this file in their
forthcoming worker brief (`docs/briefs/r3-ci-layer-2-path-conditional-
gating-worker.md`) as the starting template for Verification Mgr
(clever-tern-670) inventory finalization.

Content:
- §1 affected-set lens Dimension enum reference (cite design doc §2)
- §2 slow-test inventory grouped into 9 clusters (78 entries from
  scripts/slow-test-exemptions.txt)
- §3 path-mapping skeleton table — (test_pattern, dimension,
  required_paths_regex, confidence, dissolution_note). PM partial-
  fills high-confidence rows; ~12 [Mgr-fill] placeholders left for
  rows requiring deeper substrate-lens / consumer-tracing knowledge
- §4 open questions for Mgr (multi-dim split, conservative defaults,
  pilot cluster selection — recommended Cluster B = Lane 2 Stage 2d
  symbolic cost; high-confidence single-dimension contained module)
- §5 acceptance checklist for Mgr-fill completion
- §6 STOP triggers (new substrate carrier need; dimension outside
  enum; test-output dependency = lens not bridge)
- §7 cross-refs (Layer 1 PR #2718, lens canvas PR #2713, routing
  msg_a77c7f42, memory feedback_parallel_representation_debt)

Hard constraint per feedback_parallel_representation_debt: every row
carries a dimension: field matching the lens Dimension enum so post-
dissolution skip_* flags compute structurally as
`affected_dimensions.contains(group.dimension)` — same enum,
structural source. Prevents path-mapping schema divergence from
future lens API surface.

Dissolution trigger: gate
ci_uses_provable_minimal_affected_set_selection (R3 close-blocking;
docs/design-affected-set-lens.md §5). When the lens lands, this
template + the worker output are deleted.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — dimensions is Set<Dimension>, not single primary (codex REQUEST_CHANGES fix on PR #2721)

codex REQUEST_CHANGES on PR #2721 (review #9707) caught a semantic-
contract violation: the template asserted "every entry carries exactly
one primary `dimension:`" and post-dissolution `skip_*` computation as
`affected_dimensions.contains(group.dimension)`. This conflicts with
the locked design at `docs/design-affected-set-lens.md` §2:

  affected_set(Dag_before, Dag_after) =
    ⋃ over dim in {Value, Cost, Complexity, Effect, Refinement}
      affected_set(Dag_before, Dag_after, dim)

A test that reads BOTH Cost AND Complexity (e.g., D-cluster LBP
demonstration; lane2_stage_2f composed-matches-lens) would be silently
skipped when only Complexity changes if its dimension is narrowed to
"Cost." That's `INVARIANTS.md` P2 single-authority violation against
the locked lens design.

Fixes:
- §1: rewrite from "exactly one primary dimension" to "dimensions is
  Set<Dimension> = full read-set; affectedness is union semantics"
- Header bullet: hard constraint reframed — multi-dim REQUIRED when
  consumer reads multi; post-dissolution math is `(affected ∩ row.dimensions) ≠ ∅`
- §3 table: column rename `dimension` → `dimensions`; rows updated:
  - D-cluster LBP, lens_cost_target_realization, cost_lens_consumer:
    expanded to multi-dim sets [Complexity, Cost], [Cost, Value]
  - lane2_stage_2f_dimension: [Complexity, Cost] (composed-matches-lens)
  - F-`m0_acceptance` + I-`thesis_validation_test`: full 5-dim set
    (compile-boundary + thesis-level read every dim)
  - G-`t_las_crdt_cost_basis_demo`: [Cost, Effect, Value]
  - G-`r3_free_consequences_second_batch`: [Cost, Value]
  - H-`t_ci_workflow_as_data_demo`: [Value, Cost] (DimensionReport timing)
  - All single-dim rows (A, B, Most-C, etc.): formatted as set `[Cost]`
- §4 Open question 1: rewrite to forbid narrowing, mandate ADD-when-doubt
- §5 acceptance: add dim-set-semantics + union-formula checks
- §6 STOP triggers: add "tempted to narrow set → STOP and EXPAND"

Director's Layer 2 brief at PR #2719 has the same singular-`dimension:`
shape and likely has the same finding waiting to surface; will flag to
Director after this lands.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template count + wording fixes (cursor BLOCKING #9719 on PR #2721)

cursor BLOCKING REVIEW on PR #2721 (review #9719 at dedcf69) caught
factual count discrepancies + the stale singular `dimension` echo
that openai-pro had flagged as non-blocking:

1. Cluster A banner — was "(~10)", actual sum = 1+6+2+6 = 15 → fixed to "(15)"
2. Cluster B individual-row count "6" while listing 7 names → fixed to 7;
   banner "(~6)" → "(7)"
3. emit_matrix Notes "5× emit matrix sweep" while listing 6 tests
   (3 module + 3 program) → fixed to "6× emit matrix sweep (3 module
   + 3 program)" for explicit attribution
4. Cluster D banner "(~5)", actual sum = 2+3+2+2 = 9 → fixed to "(9)"
5. Line 7 (Purpose) stale singular `(test_pattern, dimension,
   required_paths_regex)` echo → fixed to `dimensions` plural;
   converges with openai-pro APPROVE_WITH_COMMENTS observation (review
   #9714) that had been deferred to follow-up — cursor's BLOCKING
   verdict overrides the deferral

§4 Open question 5 (pilot recommendation) also corrected from
"~6 tests" to "7 tests" for Cluster B consistency.

Clusters C/E/F/G/H/I banner counts re-verified against table sums
(7/12/6/10/7/5 respectively) — all already exact, no change needed.

P1 Modeling Faithfulness restored: every cluster banner now matches
its enumerated tests-column sum.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — fix skip_<cluster> polarity (openai-pro BLOCKING #9721 on PR #2721)

openai-pro re-review on PR #2721 at sha 93080af caught a critical
boolean polarity inversion in the skip_<cluster> formula. A Mgr/worker
following the brief literally would have wired the CI gate backward,
silently skipping affected tests — TESTING.md "test selection must
not skip affected behavior" violation + Boundary Discipline violation
(boolean carrier name and contract encoded opposite meanings).

**The bug**: 4 places stated post-dissolution `skip_<cluster>` formula
as `(affected_dimensions ∩ group.dimensions) ≠ ∅` (skip when
intersection NON-empty), while the CI consumer wires
`if: skip_<cluster> != 'true'` (run when skip is NOT true). Combined:
when intersection is non-empty (= affected), skip=true → tests don't
run → affected tests silently skipped.

**The fix**: invert the formula to `(intersection = ∅)` (skip when
intersection IS empty = no affected dim that this cluster reads). The
CI gate semantics stay the same; the polarity correction is on the
post-dissolution lens mapping.

Sites corrected:
- §1 hard-constraint para (line 9): replaced "(non-empty intersection
  means run)" with an explicit Boolean polarity block defining
  `skip = (intersection = ∅)` and equivalent `run = (intersection ≠ ∅)`
- §3 path-mapping intro (was line 132, now 142): same polarity fix
  + "Equivalently: `run = (intersection ≠ ∅)`"
- §4 open-question 4 (was line 186, now 196): "skip_<cluster> becomes
  `(intersection ≠ ∅)`" → `(intersection = ∅)` with explicit
  "same polarity: skip when no affected dim" note
- §5 acceptance (was line 206, now 216): same polarity fix +
  explicit "inverting the polarity silently skips affected tests" warning

All 4 references now consistent. Polarity table:
  intersection = ∅  → skip=true  → "do not run" (NOT affected, safe to skip)
  intersection ≠ ∅  → skip=false → "run" (affected, must run)

Director's brief #2719 likely has the same polarity issue and will need
parallel fix from the same authority chain. Flagging separately.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — cluster aggregation + path-regex verification discipline (codex BLOCKING on PR #2721)

codex BLOCKING review on PR #2721 at sha 262f42d caught two
substantive gaps:

**(1) Cluster aggregation predicate missing**: §3 defined per-row
intersection check but didn't specify how multi-row clusters
aggregate to the cluster-level `skip_<cluster>` boolean. A worker
following the brief could implement disjunction (any-row-empty
= skip cluster) which would silently skip the OTHER affected rows
in the cluster when only one row is unaffected.

Fix: explicit conjunction predicate in §3 + §4 + §5 + §6:
  skip_<cluster> = ∀ row ∈ cluster : (changed_files ∩ row.regex) = ∅
Equivalently: run_<cluster> = ∃ row ∈ cluster : row affected.

**(2) Path regexes PM-authored without source-tree verification**:
PM concrete `required_paths_regex` values in §3 were manually
authored from the inventory SHA references without validation
against actual paths in the source tree. Workers might wire CI
gates against stale paths.

Fix: explicit Mgr-verification discipline in §3 + §4 + §5 + §6:
- Workers MUST validate each concrete regex against source tree
  at HEAD before CI implementation
- Unverified or unverifiable regexes → `.*` per conservative
  fail-closed default
- Confidence column treated as audit priority (low → `.*` first,
  medium → audit then decide, high → audit but likely fine)
- Validation record kept (PR description or commit message)

Both fixes preserve the locked-design polarity from earlier
revisions:
- Per-row formula stays `(intersection = ∅)` for skip semantic
- Cluster aggregation is conjunction over rows (∀)
- Run formula is the structural complement (∃ ↔ ≠ ∅)

All 4 places updated: §3 path-mapping skeleton intro + §4 mechanism
+ §5 acceptance + §6 STOP triggers. Brief now structurally
guards against:
- polarity inversion (skip = ∅, not ≠ ∅; openai-pro caught prior)
- dimension cardinality narrowing (Set<Dimension>, not single; codex
  caught prior)
- cluster aggregation by disjunction (∀, not ∃; codex caught this)
- regex authoring without source-tree validation (codex caught this)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — fix stale dsl/std/ lens-paths (codex BLOCKING inline at line 152)

codex BLOCKING inline-review at line 152 (sha 262f42d) caught
that Cluster B's regex used stale `dsl/std/lens_cost.*\.dag` +
`dsl/std/cost.*\.dag` paths while the live cost-lens authority
is at `src/v3/lenses/cost.dag`. A change to the live authority
file would NOT match the stale regex → skip_b=true → cost-lens
tests silently skipped (P3 fail-closed + P2 single-authority
violation).

**Systematic audit + fix**: stale `dsl/std/<lens>.dag` pattern
applied across many rows (PM authored assuming lens .dag lived
in dsl/std/, but the live tree has them at src/v3/lenses/):

| Row | Old (stale)                                    | New (verified)                                                 |
|-----|------------------------------------------------|----------------------------------------------------------------|
| B   | dsl/std/lens_cost.*.dag + dsl/std/cost.*.dag   | src/v3/lenses/cost(_target_realization)?.dag                   |
| C-i | dsl/std/lens_idempotency.*.dag                 | src/v3/lenses/idempotency.dag                                  |
| C-p | dsl/std/lens_provenance.*.dag                  | src/v3/lenses/(provenance\|emission_provenance).dag            |
| C-u | dsl/std/lens_unused_parameters.*.dag           | src/v3/lenses/unused_parameters.dag                            |
| E×4 | dsl/std/(complexity\|cost\|symbolic_cost).*.dag | src/v3/lenses/(complexity\|cost).dag                           |
| F-b | dsl/std/boolean_algebra.*.dag                  | dsl/std/logic.dag (boolean-algebra concepts live there)        |
| G-c | dsl/std/complexity.*.dag                       | src/v3/lenses/complexity.dag                                   |
| G-l | dsl/std/(cost\|las\|crdt).*.dag                | `.*` (Mgr-fill; T-LAS substrate-deps not PM-traced yet)        |
| H-2 | dsl/std/parse.*.dag                            | src/v3/std/parse_surface.dag + src/v3/compiler/parse_tables.dag|
| H-2c| dsl/std/parse_tables.*.dag + dsl/std/tokenize  | src/v3/compiler/parse_tables.dag + src/v3/(compiler\|std)/tokenize.dag |
| H-w | dsl/std/workflow.*.dag                         | src/v3/std/workflows.dag                                       |

Confidence column dropped from `high` to `medium` for all
post-correction rows — Mgr should still validate each path
against live source tree at HEAD before CI implementation per
the verification-discipline added at d19a1a0. dissolution_note
column carries inline "**Path correction**: ..." annotations
documenting each fix for reviewer audit.

Cross-cluster bug-class catches now mapped on this template:
1. Dimension cardinality (Set<Dimension>; dedcf69)
2. Boolean polarity (skip = ∅; 262f42d)
3. Count discrepancies + line-7 singular (93080af)
4. Cluster aggregation predicate (∀ not ∃; d19a1a0)
5. Path-regex verification discipline (d19a1a0)
6. **Stale dsl/std/ lens-paths corrected to src/v3/lenses/** (this fix)

Brief structurally validated across 6 distinct axes.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — fix regex alternation escape (openai-pro APPROVE_WITH_COMMENTS on #2721)

openai-pro APPROVE_WITH_COMMENTS on PR #2721 at sha 45fc195 caught
a non-blocking regex error: line 185 had `src/v3/(compiler\|std)/tokenize.dag`
with `\|` (markdown-cell pipe escape), which a regex engine would
interpret as the literal string `compiler|std`, NOT as alternation
between `compiler` and `std`.

Mechanism of the bug:
- Markdown tables use `|` as column separator
- To put a literal `|` IN a cell (outside backticks), you escape with `\|`
- PM authored the regex with `\|` thinking the markdown-table escape
  was needed, but the regex is INSIDE backticks (code span) which
  preserves pipe character literally
- A worker copying the regex into ci.yml would silently miss
  tokenize.dag changes (only matches literal `compiler|std/tokenize.dag`)

Fix: drop the unnecessary `\` escape; markdown code spans preserve
`|` literally. Now regex correctly reads
`src/v3/(compiler|std)/tokenize.dag` — alternation between
src/v3/compiler/tokenize.dag and src/v3/std/tokenize.dag, both of
which exist per the source tree verified at 45fc195.

Mitigation: the template's own validation discipline at §3 + §5 §6
(workers MUST validate regex against live source tree before CI
implementation) would have caught this, but per openai-pro's read
"the concrete row should still not carry a known-bad example" — fair.

Cumulative bug-class catches on this template now 7 axes hardened:
1. Dimension cardinality (Set<Dimension>; dedcf69)
2. Boolean polarity inversion (skip = ∅; 262f42d)
3. Count discrepancies + line-7 singular (93080af)
4. Cluster aggregation predicate (∀ not ∃; d19a1a0)
5. Path-regex verification discipline (d19a1a0)
6. Stale dsl/std/ lens-paths corrected (45fc195)
7. Markdown-cell-escape leaking into regex semantics (this fix)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — Dimension enum is OPEN per design §2 + THESIS user-defined dims (codex BLOCKING on PR #2721)

codex BLOCKING inline-review at line 186-ish caught that my §6 STOP
trigger hard-rejected any `dimensions:` element outside the built-in
base set `{Value, Cost, Complexity, Effect, Refinement}` — which closes
the user-extensibility surface that THESIS + docs/design-affected-set-
lens.md §2 leave intentionally open with the trailing `...`.

Verification (codex was correct):

- `docs/design-affected-set-lens.md` §2: `⋃ over dim in {value, cost,
  complexity, effect, refinement, ...}` (note ellipsis = open enum)
- `THESIS.md` "User-defined dimensions" section: 'User-declared
  dimensions extend the same structural proof surface ... the ceiling
  of what gunbc can prove is user-extensible.'

The built-in base set ≠ the full enum. My template was treating them
as equivalent, which would have rejected valid user-defined dims at
the STOP gate (INVARIANTS P1 single-authority violation against
THESIS/design + P3 fail-closed violation since rejection-instead-of-
fail-closed is the opposite of safety).

Fixes:
- **§1** Dimension enum reference: rewrote with explicit `Dimension =
  {value, cost, complexity, effect, refinement, ...}` notation + the
  trailing `...` annotated as "OPEN for user-defined" + paragraph on
  THESIS user-extensibility framing + explicit instruction to treat
  unknown dim as fail-closed (always-run), NOT reject
- **§5** acceptance criterion: updated to reference the open enum +
  fail-closed-for-unknown behavior
- **§6** STOP trigger: now reads "cannot be carried as a typed
  Dimension at all (e.g., string-as-dimension, runtime-only)" — that's
  the genuine structural failure. Encountering a NEW user-defined
  dimension is NOT a STOP; it's a row carried as fail-closed-always-run

Cumulative bug-class catches on this template now 8 axes hardened
(was 7 before this fix; ci-skip-pattern-script wasn't applicable here):
1. Dimension cardinality (Set<Dimension>; dedcf69)
2. Boolean polarity inversion (skip = ∅; 262f42d)
3. Count discrepancies + line-7 singular (93080af)
4. Cluster aggregation predicate (∀ not ∃; d19a1a0)
5. Path-regex verification discipline (d19a1a0)
6. Stale dsl/std/ lens-paths corrected (45fc195)
7. Markdown-cell-escape leaking into regex semantics (7cbf29f)
8. **Dimension enum hard-closed rejecting user-defined** (this fix) —
   THESIS + design doc §2 explicitly leave open

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — carry user-defined Timing dim explicitly (codex BLOCKING on PR #2721)

codex BLOCKING re-review at sha c61a7ed line 197 (~193 in their
relay) caught a narrowing residual after the prior open-enum fix:
the `t_ci_workflow_as_data_demo_test` row carried `[Value, Cost]`
but the test actually evaluates `DimensionReport<TimingMeasurement>`
/ `ci_modeled_timing` — a user-defined Timing dim distinct from
generic Cost.

My prior open-enum fix (c61a7ed) updated §1/§5/§6 to ALLOW user-
defined dims but I didn't fix THIS row to USE one. Per the just-
established 'carry the dim, don't narrow' framing in §6, this row
should carry `[Value, Cost, Timing]` (or just `[Value, Timing]` if
Cost is sufficiently distinct from Timing in the test).

**Why it's load-bearing**: a future timing-only delta (e.g.,
DimensionReport schema change touching only timing fields, not Cost)
would be 'affected' for this test under the lens but the prior row
narrowed Timing → Cost → if Cost.affected = empty but Timing.affected
non-empty, test would be silently skipped (TESTING.md violation +
THESIS user-defined-dims framing violation).

Fix:
- Row dimensions: `[Value, Cost]` → `[Value, Cost, Timing]`
- Row dissolution-note: explicit annotation citing
  `DimensionReport<TimingMeasurement>` + `ci_modeled_timing` user-
  defined dim + the carrying-vs-narrowing rationale
- Self-references this template's own open-enum support per §1 —
  the row is now an in-table demonstration of the open-enum framing
  (consistency between framing and example)

This also re-stress-tests cluster aggregation: cluster H aggregates
over multiple rows including this Timing-carrying row, so cluster-
level skip computation correctly fail-closes when ANY row's dim
intersects with affected_dims.

Cumulative bug-class catches on this template now 9 axes hardened:
1. Dimension cardinality (Set<Dimension>)
2. Boolean polarity inversion (skip = ∅)
3. Count discrepancies + line-7 singular
4. Cluster aggregation predicate (∀ not ∃)
5. Path-regex verification discipline
6. Stale dsl/std/ lens-paths corrected
7. Markdown-cell-escape regex
8. Dimension enum hard-closed (open per THESIS)
9. **Narrowing user-defined dim to built-in** (this fix; carry don't normalize)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — codify 3-arm regex completeness invariant (mirror Director PR #2727 worker-brief discipline)

Director's PR #2727 absorbed Brian inline + codex BLOCKING convergent
finding on post-#2719 fail-open hole: per-group regex must include
THREE arms — deps + test-source + fixture — missing any is a
P3 fail-open boundary class.

This template (PR #2721) had the same structural issue: most PM-
authored rows have arms (1) deps + (2) test-source but lack arm (3)
`tests/dag/*.dag` fixture explicitly. Per Director's canonical
worker-brief discipline (PR #2727), this mirrors the gap and adds
the 3-arm completeness invariant to align.

Updates:
- §3 path-mapping intro: explicit 3-arm completeness invariant + per-
  arm fail-open semantics + audit note that PM-authored rows in §3
  below need Mgr fixture-arm audit for tests reading from
  `tests/dag/*.dag` (e.g., `t_pb_b_1_dag_runner_test` consumes
  `tests/dag/t_pb_b_1_*.dag`)
- §5 acceptance: new checklist item — every concrete regex includes
  arms (1) + (2) + (3) where applicable; Mgr-fill rejects missing
  arms 2/3
- §6 STOP triggers: two new STOP triggers for missing test-source
  arm OR missing fixture-arm-when-applicable
- Cross-link to Director PR #2727 / #2719 for canonical framing

This codifies but does NOT retrofit existing §3 rows — that's
Mgr-fill audit work (per the §3 disclaimer + Mgr-fill discipline).
PM signals the gap; Mgr fixes per row.

Cumulative bug-class catches on this template now 10 axes:
1. Dimension cardinality (Set<Dimension>)
2. Boolean polarity inversion
3. Count discrepancies + line-7 singular
4. Cluster aggregation predicate (∀ not ∃)
5. Path-regex verification discipline
6. Stale dsl/std/ lens-paths
7. Markdown-cell-escape regex
8. Dimension enum hard-closed (open per THESIS)
9. Narrowing user-defined dim (Timing→Cost)
10. **Missing test-source/fixture arms in regex** (this fix mirroring
    Director PR #2727 worker-brief discipline)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — restore `...` ellipsis in quoted §2 union formula (cursor APPROVE_WITH_COMMENTS-level exploratory on PR #2721)

cursor APPROVE review #9858 at sha 5c227c5 noted an exploratory
inconsistency: my quoted design-doc §2 union formula at lines 48-51
enumerated only the 5 built-in dimensions without the trailing `...`
that the actual `docs/design-affected-set-lens.md` §2 has, while my
surrounding text (lines 27-33, §1 enum reference) stresses the open-
enum framing.

Fix: restore the `...` in the quoted formula + add inline annotation
'← OPEN per §2; user-defined dims extend' so Mgr-fill readers can't
misread the box as closed.

Now lines 27-33 (open-enum framing) + lines 48-51 (formula quote) +
§5 acceptance + §6 STOP triggers all consistently affirm the open-
enum framing per THESIS user-defined dimensions.

Non-blocking exploratory observation; quick fix because the cost is
trivial (1-char + comment) and the value is internal-consistency
preservation.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — add test-source arm to 4 rows violating own 3-arm invariant (codex BLOCKING on PR #2721)

codex BLOCKING REQUEST_CHANGES at sha 8f11a35 caught my OWN 3-arm
completeness invariant being violated by 4 rows that ship concrete
regex but lack test-source arm. Per the invariant I codified in §3 +
§5 + §6, every concrete regex MUST include the OWN test-source arm
under `src/v3/compiler/tests/integration/`. These rows didn't:

1. `dimension::analyze_complexity_tests::.*` — had `tests/integration/dimension.*\.rs` arm but that file doesn't exist (tests live inline as a module in `tests/integration.rs`); arm matched nothing → fail-open
2. `dimension::fail_closed_tests::.*` — NO test-source arm
3. `e7_analyze_complexity_integration::.*` — NO test-source arm
4. `lane2_stage_2f_dimension_test::.*` — NO test-source arm
5. `sg2c1_parse_tables_authority_test::.*` — NO test-source arm

Fix: add test-source arm to each row:
- For inline modules (dimension/e7/lane2_stage_2f): test lives inline
  in `src/v3/compiler/tests/integration.rs`; add that path. Broad-but-
  correct per fail-closed default (any edit to integration.rs triggers
  these tests; a finer-grained match isn't expressible via path regex
  because the modules are inline in the file).
- For sg2c1 (standalone file): add explicit
  `src/v3/compiler/tests/integration/sg2c1_parse_tables_authority_test\.rs`.

Each row's dissolution_note now carries inline annotation citing the
codex BLOCKING finding + the test-source-arm correction rationale.

**Lesson**: codifying the invariant in §3/§5/§6 doesn't retrofit
existing rows — needed to AUDIT each concrete regex against the
invariant after codification. PM did partial audit on path correctness
(dsl/std → src/v3/lenses) but didn't re-audit for test-source-arm
presence. cursor #9858 noted earlier the boxed-formula inconsistency
in §1; codex now caught the same class on §3 row content. Audit
discipline = match-the-framing-everywhere, not just-codify-the-framing.

Cumulative bug-class catches on this template now 11 axes hardened:
1. Dimension cardinality (Set<Dimension>)
2. Boolean polarity inversion
3. Count discrepancies + line-7 singular
4. Cluster aggregation predicate (∀ not ∃)
5. Path-regex verification discipline
6. Stale dsl/std/ lens-paths
7. Markdown-cell-escape regex
8. Dimension enum hard-closed (open per THESIS)
9. Narrowing user-defined dim (Timing→Cost)
10. 3-arm regex completeness invariant codified
11. **Existing rows violated own 3-arm invariant** (this fix — codification didn't retrofit)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §1.8 row #105 — symbolic_cost_textbook_coverage_landed (Path A Tier 1 ratified per Director msg_ad5e934d) + §1.2/§1.5 interrogation probe refinement

Operator directive 2026-05-13 ("anything you would find in an algorithms textbook ... we need to land this all in R3 please") + Director ratification msg_ad5e934d (RATIFIED Path A + Tier 1 IN-R3 + Tier 2 R4-deferred + 5 sub-canvas questions routed to Substrate Mgr).

§1.8 row #105 changes:
- New gate symbolic_cost_textbook_coverage_landed; substrate-shape predicate-family; T-CostLens-Composition lane
- Tier 1 carrier extension: PROMOTE PolynomialCost { degree: DegreeAtLeastTwo } -> { degree: Rational } per dsl/std/rational.dag:26 Field<FieldOfFractions<Int>>; ADD PolyLogCost { exponent: Int } + ExponentialCost { base: Int } + FactorialCost; net 7 -> 11 variants per src/v3/std/algebra.dag:190-197
- Tier 2 R4-deferred: LogLogCost / InverseAckermannCost / IteratedLogCost / HyperExponentialCost (each requires consumer-evidence trigger)
- 5 sub-canvas questions for warm-wolf-698: (Q1) Rational dominance lattice ordering (Field<FieldOfFractions> lacks Order); (Q2) Linear-vs-Polynomial split reconciliation; (Q3) Sum/Product algebra interaction rules; (Q4) STOP-SIGNAL update; (Q5) canvas-shape authoring
- Two-part predicate: Part A (carrier landed via grep on type SymbolicCost) + Part B (algebra rules pass via cargo test)
- 5 Director-enumerated anti-patterns for post-ratification reviewers

§1.8 header gate-count updates (multiple lines):
- 104 enumerated -> 105 enumerated across plan, Q1 row, R3-close target arithmetic
- 103 R3-load-bearing -> 104 R3-load-bearing (only #11 canvas-deferred subtracted)
- Authority history extended: +Director ratification msg_ad5e934d + cost-textbook-coverage row #105 added 2026-05-13

§1.2 (Cost) interrogation probe refinement (post-PR-#2822 fix-forward):
- Promise updated to include #105 + R3-committed Tier 1 scope verbatim
- Split into Implementation probes (carrier scope) + Scope probes (Tier 1 textbook coverage with concrete bound examples: √n, exp, factorial, polylog, matrix mult) + Tier 2 boundary probes (R4-deferred bounds with expected behavior) + Falsification probes (Tier-3 recursive, Tier-2-not-named, STOP-SIGNAL trigger for Tier-1-coverable bound collapsing to UnknownCost)

§1.5 (User-defined dimensions) escape-hatch probes for Tier 2+:
- Compositional-mechanism probe per Director structural-extension caveat (if user-defined-dim supports cost-variant authoring with dominance lattice integration, Tier 2 R4-deferral is structurally bounded)
- Falsification probe: author a user-defined cost lens for inverse Ackermann; if it integrates -> R4-deferral bounded; if not -> load-bearing gap

Effort estimate: ~3-4 weeks total substrate work (carrier change + dominance lattice + Sum/Product algebra + testgen + parity validation); R3 close timeline extends accordingly.

Cascade: PM §1.8 row added (this PR) -> Substrate Mgr authors canvas (Q1-Q5) -> Director ratifies canvas -> worker dispatch -> gate #105 CONSUMER_LANDED -> PASSING through standard cycle.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §1.5/§1.7/§1/§3 — comprehensive 104→105 / 103→104 count sweep (operator BLOCKING on PR #2824:85 INVARIANTS P2)

Operator briansrls flagged at `docs/r3-program-plan.md:85` that PR #2824
introduced "105 enumerated" while the same §1.5 block still said "104
gate IDs" and "103 R3-load-bearing arithmetic", creating competing
authorities (INVARIANTS P2).

PR #2824's prior commit message claimed a header count sweep but the
diff only updated SOME of the count sites, leaving 10 lines internally
inconsistent. This commit completes the sweep.

Lines updated (all 104→105 / 103→104 where the count was a TOTAL or
LOAD-BEARING reference, not a row-number reference):

- §1.5 line 84: "104 gate IDs enumerated at this commit" → "105 gate IDs"
- §1.5 line 86: "103 R3-thesis = 104 − 1" → "104 R3-thesis = 105 − 1"
- §1.5 line 88: "forward-looking R3 close target is 103" → "104"
- §1.5 line 90: "Total: 87 + 16 + 1 = 104" → "Total: 87 + 16 + 2 = 105"
  (the +2 represents #104 + #105 routed to T-Lens-Behavioral-Parity +
  T-CostLens-Composition respectively; kept in trailing tail vs
  lane-incorporated to preserve the 2026-05-12 lane-breakdown snapshot's
  audit shape)
- §1.5 line 96: "103 R3-thesis = 104 − 1 = 103" → "104 = 105 − 1 = 104"
- §1 line 114: "103 R3-load-bearing gates green" → "104"
- §1.7 line 125: "DECLARE 104 closure gates" → "105"
- §1.8 line 338: "103 load-bearing" → "104"
- §2 line 627: "103 load-bearing" → "104"
- §Q-table line 805: "104 closure gates total" → "105"

Lines NOT updated (correct references to row numbers, not count totals):
- Lines 8, 84, 88, 90, 98, 108, 111, 148, 239 references to gates
  #98-#103 (T-WAD FULL R3) and gate #104 (Miss-class) and gate #105
  (cost-textbook) — these are row-number references, not totals
- §1.8 line 331/332 row entries (gate #103 ci_uses_affected_set,
  gate #104 lens_read_witness_shape_dissolved) — row identifiers

INVARIANTS P2 single-authority restored across §1.5 / §1.7 / §1 close
criteria / §2 close criteria / §Q-table.

Lesson: header-count sweep PRs MUST grep-verify every occurrence of
the prior counts before claiming the sweep is complete. PR #2824's
prior commit message overstated coverage; operator caught.

— sent from deep-wolf-155

* docs(r3-structure): add gate #104 + #105 to §Acceptance — restore single-authority parity with §1.8 (operator BLOCKING on PR #2824:207 INVARIANTS P2)

Operator briansrls flagged at `docs/r3-program-plan.md:207` that PR #2824
claims "the 105-gate ledger is consolidated with r3-structure.md" but
the diff doesn't update r3-structure.md, leaving #105 without the
canonical acceptance body that line 340 says lives there.

Audit found the gap is wider than #105 alone — gate #104
(`lens_read_witness_shape_dissolved`, added 2026-05-12 in a prior PR)
is also missing from r3-structure.md §Acceptance. Same INVARIANTS P2
single-authority violation class.

Fixed both in PR #2824 (cleanest bundle — same gap class, both rows
added to §Acceptance in their canonical lanes):

- **#105 `symbolic_cost_textbook_coverage_landed`** added to
  T-CostLens-Composition lane (after `cost_lens_reads_target_realization`
  + `coercion_cost_equals_complexity_by_construction`). Encodes Path A
  Tier 1 carrier extension shape (PolynomialCost{degree: Rational} +
  PolyLogCost + ExponentialCost + FactorialCost) + Tier 2 R4-deferral
  + structural-extension caveat + two-part predicate (Part A carrier
  landed + Part B algebra rules pass). Cross-refs §1.8 row #105 for
  full receipt + 5 sub-canvas substrate-shape questions.

- **#104 `lens_read_witness_shape_dissolved`** added to
  T-Lens-Behavioral-Parity lane (after `lens_capability_register_zero_
  proxy_zero_stub`). Encodes bundled-migration shape per Director
  ratification msg_915aa2c1 — (1) substrate-level Miss→Violates
  collapse across 70 sites in 6 files (cost.dag/complexity.dag/
  infer_helpers.dag/algebra.dag/substrate.dag/lookup.dag); (2)
  testgen-level universal-coverage TestClaim. Two-part predicate
  (Part A terminal + Part B regression guard). Cross-refs §1.8 row
  #104 for full receipt.

INVARIANTS P2 single-authority restored: §1.8 ledger ↔ §Acceptance
canonical body now in parity at gate-ID level for all 105 enumerated
gates (104 R3-load-bearing post-canvas-deferral).

Lesson logged: when adding §1.8 rows, r3-structure.md §Acceptance
must update in same PR. Prior PR #2824 commit message did not
include this discipline; #104's prior PR also missed it. Class
violation traceable to: section-anchor authoring discipline that
prevents the missing-mirror class.

— sent from deep-wolf-155

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
* docs(briefs): S6 brief fix-forward — authority chain corrected per codex BLOCKING review on PR #2782 sha b28cf88

Earlier brief mis-cited high-level T-WAD substrate-shape framing; codex caught that the actual implementation authority for affected-set selection is:
- PR #2713 (upstream affected-set lens substrate; merged) per docs/design-affected-set-lens.md §2
- docs/design-t-wad-slice-7-binary-shim-affected-set-selection-canvas.md in main (§1 BinaryShim consumption / §3 fail-closed / §4 selection algorithm / §5 path-regex removal invariant)
- PR #2766 harness contract + Layer 2 path-regex inventory ratchet

§0 + §1 rewritten to encode the correct authority chain, canvas §4 algorithm verbatim, and canvas §5 path-regex removal invariant. STOP conditions tightened to the actual fail-closed surfaces (PR #2713 serialization form, path-regex inventory drift).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S6 brief — surface 2-layer decomposition per canvas §6-§7 staging (substrate prerequisite + BinaryShim consumer/runner) — swift-wren-365 msg_29f68109

Earlier draft compressed both layers into one PR. swift-wren-365 surfaced (correctly) that PR #2798 in-flight is Layer 1 substrate (closure+topo over CIWorkflowDag + CiWorkflowDiff) — Layer 2 (BinaryShim consumer of PR #2713 lens output + TestClaim D(t)/Δ(t) mapping + canvas §5 path-regex removal) is a follow-on PR depending on Slice 5 BinaryShim hook per canvas §6-§7.

§1 reframed as two-layer decomposition with explicit scope boundaries. Phase A-C explicitly scoped to Layer 2. Layer 1 in-flight under PR #2798 not in this brief's scope.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S6 brief §4 PR-body framing + §6 reference list harmonized with §1 canvas-vs-PR-#2766-harness split — cursor APPROVE 10477 exploratory note

§4 PR body framing now distinguishes three authority types: canvas (BinaryShim consumption + selection algorithm + path-regex removal) + upstream lens (PR #2713 / design-affected-set-lens.md) + harness/ratchet (PR #2766). §6 reference list expanded similarly. Removes the residual 'PR #2766 substrate authority' phrasing that conflicted with §1's three-source split.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #62 file-ingestion substrate-shape canvas

Surfaces the substrate-shape question for §1.8 row #62
substrate_gap_file_ingestion_closed before brief authoring.

bright-otter-731 was auto-spawned on this gate without an
authored brief and surfaced a clean audit (no include_str! at
HEAD in dsl/; PR #2819 read_utf8_file candidate shape held in
draft). §4.3 line 505 frames closure as workflow_substrate
extension to file-attachment (Candidate B), but PR #2819 implements
compile-time UTF-8 read (Candidate A) — parallel-authority risk.

This canvas frames the candidate shapes (A/B/C/d) for Director-or-
Substrate-Mgr-tier ratification before brief authoring proceeds.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #62 FileAttachment carrier-internals sub-canvas

Director ratified Candidate (b) on PR #2820 — workflow-substrate
FileAttachment carrier extending #53 — per PM msg_52c4a707. This
sub-canvas surfaces carrier internals (type def + fields + workflow
coupling + Practice 4 + lazy-vs-eager) for next-tier ratification
per recursive feedback_substrate_shape_belongs_in_mgr_canvas.

Three candidate shapes (B-1 minimal / B-2 path-keyed / B-3 anchor+entry
pair) anchored against gate #55 WorkflowObservationAnchor precedent at
src/v3/std/timing_lens.dag:98 (already CONSUMER_LANDED).

Director anti-patterns encoded for worker review enforcement.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #62 FileAttachment worker brief (Refined-B-1 ratified)

Director ratified Refined-B-1 carrier shape with full §8 Q1-Q6
dispositions + 7 anti-patterns per PM msg_bc8c23f6 (relaying Director
msg_61e302c6). Worker brief authored with:

- Exact 5-field carrier (subject_node + content_digest + producer_id +
  workflow_run_id + attached_at_ns) — strict 5-of-7-subset of #55
  WorkflowObservationAnchor
- Q1-Q6 dispositions encoded verbatim for reviewer enforcement
- 7 anti-patterns receipt-of-compliance requirement
- Phase A (carrier) / Phase B (ratchet test) / Phase C (existence-proof
  use case) / Phase D (ledger update) staging
- 5 STOP conditions including consumer-evidence-blob-store gap
- Workflow blob-store substrate flagged as Wave-2 sub-canvas-2 trigger
  (forward-looking, NOT blocking this brief)

Brief is DISPATCH-READY. PR #2819 stays held as Candidate A drift
(anti-pattern #1).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 SymbolicCost Tier 1 carrier-extension canvas

Director ratified Path A Tier 1 on 2026-05-13 (PM msg_4fd650b7
relaying msg_ad5e934d) with 5 sub-canvas questions Q1-Q5 routed
to Mgr. This canvas surfaces dispositions on each for next-tier
ratification before worker brief authoring.

Mgr recommendations:
- Q1 Rational ordering: c (layered OrderedField + lazy migration)
- Q2 Linear-vs-Polynomial: Y (collapse to PolynomialCost(degree=1)
  per §P5; net 10 variants not 11)
- Q3 algebra rules: tabulated 10 new interaction rules; PolyLog
  reserved for log^k only (n log n stays composite); Factorial²
  = UnknownCost (Tier-2 R4-deferral receipt)
- Q4 STOP SIGNAL: re-resets at 11th variant (or 12th if Tier-2)
- Q5 carrier-shape canvas: this document
- §8 Tier-2 mechanism: defer to R4 (InverseAckermann doesn't
  fit IteratedAlgebra; no uniform compositional surface)

5 Director anti-patterns encoded + 2 Mgr-derived for worker review.

Gates on §1.8 row #105 PR #2824 landing + Director ratification of
§12 questions before worker dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 SymbolicCost Tier 1 worker brief (canvas ratified)

Director ratified canvas PR #2828 Q1-Q5 + §8 Tier-2 disposition per
PM msg_a055c38b relaying msg_d86a5987. Worker brief encodes ratified
shape as single coordinated PR with 7 sub-phases:

- Phase A: OrderedField<T> witness landing + Rational re-declaration
- Phase B: STOP SIGNAL rewrite (cap at 11)
- Phase C: SymbolicCost carrier reshape (Q2-Y collapse Linear)
- Phase D: algebra interaction rules (13-rule table; §5.1 composite
  for poly·log; §5.2 (n!)² → UnknownCost verbatim)
- Phase E: bootstrap ratchet test
- Phase F: cost-lens consumer migration (LinearCost → PolyCost(d=1))
- Phase G: §1.8 row #105 ledger update

7 anti-patterns + 5 reviewer ratchets + 6 STOP conditions encoded.
DISPATCH GATES on PR #2824 (row anchor) AND PR #2828 (canvas) both
merged; brief is ready when cascade clears.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — encode invariants in type carriers (codex BLOCKING fix)

codex BLOCKING #10726 on PR #2828 (Practice 2 + Practice 6 violations):
1. Worker brief moved invariants (degree>0, exponent≥1, base≥2) into
   fold normalizer instead of carrier — admits illegal states
2. Canvas §187 said 'Rational ≥ 0' while worker said 'degree > 0' —
   split authority on the invariant

Both findings valid. Fix:

Canvas §6 STOP-SIGNAL text:
- Replaced 'PolynomialCost(Rational ≥ 0)' with 'PolynomialCost { degree:
  PositiveRational }' + adds PolyLogCost { exponent: PositiveInt } +
  ExponentialCost { base: IntAtLeastTwo } verbatim
- Adds new "Type-level refinement carriers" subsection citing
  DegreeAtLeastTwo precedent (algebra.dag:171-173)

Worker brief §5:
- New §5.0 introduces PositiveRational, PositiveInt, IntAtLeastTwo as
  Peano-style inductive carriers (strict-mirror of DegreeAtLeastTwo)
- §5.1 SymbolicCost now uses these refinement types for fields:
  PolynomialCost.degree: PositiveRational
  PolyLogCost.exponent: PositiveInt
  ExponentialCost.base: IntAtLeastTwo
- Removed the "refinements live in fold normalizer" paragraph

Illegal states (degree≤0, exponent≤0, base≤1) now structurally
unrepresentable per Practice 2 + Practice 6.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — fix variant arithmetic 10 → 9 per operator BLOCKING

Operator BLOCKING on PR #2828 canvas:135 caught real arithmetic error:
Q2-Y removes LinearCost (-1) and adds 3 NEW variants (PolyLogCost +
ExponentialCost + FactorialCost), so net is 7 - 1 + 3 = 9, not 10.
PolynomialCost is PROMOTED (degree type changed Rational), NOT added as
a new variant — that was the counting mistake.

Confirmed variant set per canvas §6 + worker §5.1:
1. ConstantCost
2. PolynomialCost { degree: PositiveRational }
3. PolyLogCost { exponent: PositiveInt }
4. LogCost
5. ProductCost
6. SumCost
7. ExponentialCost { base: IntAtLeastTwo }
8. FactorialCost
9. UnknownCost

Total: 9 variants. Confirmed.

All references updated:
- "10 variants" → "9 variants"
- "11th variant" → "10th variant" (STOP-SIGNAL trigger threshold)
- "Net 7 → 10/11" → "Net 7 → 9"
- "variant cap at 11" → "variant cap at 10"
- "10 ratified + 1 trigger" → "9 ratified + 1 trigger"
- "STOP-SIGNAL re-reset to 11" → "STOP-SIGNAL re-reset to 10"

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — Q1 premise correction per operator BLOCKING canvas:48

Operator BLOCKING #2 on PR #2828 canvas:48 caught real authority error:
Field<T> at dsl/std/algebra.dag:294 ALREADY has compare: fn(T,T)->Ordering.
The canvas claim "Rational supports add+mul+inverse, NOT order" was wrong —
Field carries the foundational order primitive. Introducing OrderedField<T>
would create parallel order authority.

This invalidates the original Q1-c ratification premise (PM msg_a055c38b).
Q1 disposition needs RE-RATIFICATION:

Revised candidate set (canvas §3 REVISED):
- Q1-α (Mgr-rec): use existing Field.compare via Rational; lt/le/gt/ge as
  cost-lens-local free functions. Zero new substrate.
- Q1-β: extend Field<T> in-place with 6 derived predicate fields. Larger
  blast radius; mirrors OrderedRing predicate set on Field directly.
- Q1-γ: OrderedField as Field-superset via type-level inheritance. Requires
  DSL grammar prerequisite (worker grep-verifies).

Worker brief Phase A regenerated under Q1-α assumption (smallest scope):
- NO OrderedField type introduction
- NO Rational re-declaration
- Cost-lens-local rational_lt/le/gt/ge/max helpers derived from
  rational.compare (existing Field operation)

Anti-pattern #6 reworded: "Parallel order authority — adding any new
OrderedField or equivalent witness when Field.compare already exists at
algebra.dag:294 (Q1 premise-corrected anti-pattern)".

Canvas + worker brief both note re-ratification required; if Director
prefers Q1-β or Q1-γ, Phase A regenerates.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — fix unsound multiplicative absorption rules per operator BLOCKING worker:140

Operator BLOCKING caught real asymptotic-analysis error: multiplicative
absorption rules like `PolyCost(d) · ExpCost(c, v) = ExpCost(c, v)` are
UNSOUND. n^d · c^n / c^n = n^d is unbounded as n → ∞, so n^d · c^n is
NOT O(c^n) strictly. Same problem with FactorialCost · PolyCost and
FactorialCost · ExpCost.

Fix: multiplicative absorption rules removed; replaced with composite
ProductCost retention:
- PolyCost(d) · ExpCost(c, v) → ProductCost([PolyCost(d), ExpCost(c, v)])
- FactorialCost(v) · PolyCost(d) → ProductCost([FactorialCost, PolyCost(d)])
- FactorialCost(v) · ExpCost(c, v) → ProductCost([FactorialCost, ExpCost])

ADDITIVE dominance rules unchanged (those ARE sound — n^d + c^n = O(c^n)
because dominant term wins; only multiplicative absorption is unsound).

Both canvas §5 + worker brief §6 rule tables updated.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — Q1-α Director-RATIFIED; add 6th anti-pattern

Director re-ratified Q1 to Q1-α per msg_676ad4e7 (supersedes
msg_d86a5987 Q1-c), retraction explicit. Updates:

Canvas + worker brief §3:
- "PENDING re-ratification" framing removed
- Q1-c rejection cites INVARIANTS P1 + row #24 + Q-MachineConstraint-Carrier
- Q1-β + Q1-γ rejections documented (Director rationale verbatim)

Anti-patterns:
- NEW Director-ratified #6: "Introducing parallel ordered-algebraic-structure
  carriers (Ordered<X>) when underlying carrier already provides compare:
  fn(T,T) -> Ordering"
- NEW Mgr-derived #7: "Multiplicative absorption rules where one variant
  absorbs another asymptotically" (operator BLOCKING worker:140 retained as
  permanent anti-pattern receipt)

Canvas: 6 Director + 2 Mgr-derived = 8 total
Worker brief: 8 anti-patterns total (matches canvas)
PR body framing template + reviewer ratchet count updated 7 → 8

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — refinement types for PolyLogExponent + ExponentialBase per operator BLOCKING PR #2824:333

Operator BLOCKING #4 on PR #2824 (relayed via PM msg_92bc8538):
- PolyLogCost { exponent: Int } admits exponent=0 (ConstantCost dup),
  exponent=1 (LogCost dup), negative; cannot represent log^7.5 (AKS
  Tier-1 case)
- ExponentialCost { base: Int } admits base=0/1 (degenerate/ConstantCost)
- Same Practice 2/6 illegal-states-unrepresentable class as prior codex
  BLOCKING (commit 3d21cb7)

Fix:
- NEW refinement carrier ExponentialBase (Int ≥ 2; renames IntAtLeastTwo
  to PM-ledger naming per row #105 commit 8049ccd)
- NEW refinement carrier PolyLogExponent (Rational > 1; admits 7.5/AKS)
- PolyLogCost.exponent: PositiveInt → PolyLogExponent
- ExponentialCost.base: IntAtLeastTwo → ExponentialBase
- PositiveRational unchanged (PolynomialCost.degree already correctly
  bounded > 0 by this carrier)

7th Director-pending anti-pattern added: "Tier-1 variant constructed
with raw Int/Rational bypassing refinement type" (matches PM's row #105
ledger 7th anti-pattern per PR #2824:8049ccde4).

Updated counts:
- Canvas §10: 6→7 Director + 2 Mgr-derived
- Worker brief §11: 8→9 anti-patterns total

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 worker brief — pre-wire P5 receipt requirement per claude APPROVE 10773

claude review 10773 exploratory observation (non-blocking): when worker
authors symbolic_cost_tier1_carrier_test.rs, INVARIANTS P5 requires
explicit single checkable receipt (deletion / SG-0 census shrink /
named-lane deferral) in PR body. Pre-wire so worker doesn't re-derive.

Added §13 verification bullet: canonical receipt is Phase F cost-lens
consumer migration (deletes LinearCost variant + collapses fallback
dispatch paths) — that net hand-Rust deletion is the P5 receipt for the
new test file.

Also corrected refinement carrier name list (was: PositiveRational/
PositiveInt/IntAtLeastTwo; now: PositiveRational/PositiveInt/
ExponentialBase/PolyLogExponent matching the post-d93e2eaffe naming).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 worker brief — address codex BLOCKING 014544f findings 2/3/4

codex review 014544f surfaced 4 BLOCKING findings (sha pre-d93e2eaffe).
Findings 1 + partial-2 covered by intervening d93e2ea (refinement
types). Residual findings 2/3/4 addressed in this commit:

Finding 2 — refinement-mixed-with-product on PolyLogExponent:
- Previous shape was `{ numerator, denominator }` with textual "numerator
  > denominator" invariant — exact refinement-mixed-with-product pattern
  codex forbids
- New inductive shape: PolyLogExponentSuccessor | PolyLogExponentFractional
  with FractionalPart in (0, 1] structurally; whole ≥ 1 + fraction > 0
  yields value > 1 by carrier shape
- HARD STOP added: do NOT author as record-with-comment-invariant
- Worker grep-verifies DSL refinement support; if not available, ratify
  inductive shape pre-authoring

Finding 3 — cross-variable dominance gap:
- §6 algebra rules table prefaced with explicit "Variable-scoping
  precondition" — rules assume same-variable operands; different-variable
  operations preserve as SumCost/ProductCost composite, not folded by
  dominance
- Cross-variable dominance explicitly named undefined within Tier-1
  substrate (Tier-2 / polynomial-multivariate scope post-R3)

Finding 4 — P5 receipt category specificity:
- §13 verification bullet now requires "exactly ONE P5 receipt category
  with concrete path + LOC count" (not narrative)
- 3 categories enumerated: (a) hand-Rust deletion + LOC; (b) SG-0 census
  shrink + delta; (c) T-PB-B ROADMAP row + dissolution-trigger
- Phase F LinearCost removal noted as LIKELY (a) source but worker MUST
  measure actual numbers, not assume narrative-equivalence

Finding 1 (refinement-over-existing-Rational vs fresh records) surfaces a
refinement-mechanism canvas question; routed to PM/Director (no fix in
this commit; the residual product-shape for PositiveRational is preserved
pending Director disposition on substrate-refinement-mechanism).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — fix FactorialCost dominance over-reach per operator BLOCKING worker:158

Operator BLOCKING: 'FactorialCost(v) + anything = FactorialCost(v)' rule
would erase UnknownCost (conservative-top) and incomparable SizeVariable
dimensions, violating P2/P3.

Fix: expand FactorialCost addition rule from single 'anything' catch-all
to per-variant explicit enumeration:
- FactorialCost + same-variable cost (Factorial/Exp/Poly/PolyLog/Log/
  Constant) → FactorialCost (absorption valid)
- FactorialCost + UnknownCost → SumCost composite (UnknownCost is
  conservative-top per algebra.dag; NEVER absorbed)
- FactorialCost + FactorialCost different-variable → SumCost composite
  (cross-variable undefined per §6 precondition)

Same-variable precondition from prior commit (c787f75 finding #3 fix)
now explicitly applied per-rule for the FactorialCost row.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — refinement mechanism IS ratified; reshape carriers per PM msg_a52ed981

PM-grep correction (msg_a52ed981): substrate refinement-mechanism `type
X = Y where predicate` is ALREADY RATIFIED at HEAD per gunbc#828
issuecomment-4390333451 Path 3 + Director Option 2. Mgr missed grep-
verifying this when authoring path (i)/(ii) framing — same discipline
class as feedback_grep_substrate_before_naming_ratification.

Precedent: dsl/std/integer.dag:181 (`PositiveInt = Nat where gt_zero`).
KNOWN_PREDICATES registry at lower.rs:798-862:
  range / non_empty / brand / gt_zero / unicode_scalar

Reshape (worker brief §5.0 + canvas §6):
- PositiveRational = Rational where gt_zero (REQUIRES gt_zero
  allowed_carriers extension to include Rational — Phase A atomic)
- ExponentialBase = Int where range(min: 2) (IMMEDIATELY available;
  range predicate has Int in allowed_carriers)
- PolyLogExponent = Rational where gt_one (REQUIRES NEW gt_one
  predicate; allowed_carriers Rational + Int; mirrors gt_zero shape;
  Phase A atomic)
- PositiveInt reuses existing dsl/std/integer.dag:181 declaration

ZERO new authority introduced. P1 single-authority + Practice 4 + Q-
MachineConstraint-Carrier "no dual representations" all satisfied via
refinement over canonical Rational/Int carriers.

NEW Mgr-derived anti-pattern #8 added: parallel rational-number
carriers when refinement-mechanism is available (PM-grep-corrected per
msg_a52ed981 + codex 014544f finding #1).

Phase A KNOWN_PREDICATES extensions:
1. gt_zero allowed_carriers + Rational
2. New gt_one predicate (Rational + Int; Bare arg)
Both atomic with carrier landing per §P5.

HARD STOP added: do NOT author fresh records/inductive sums when
refinement is available.

Anti-pattern counts: canvas §10 → 7 Director + 3 Mgr-derived = 10;
worker brief §11 → 10 anti-patterns total.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 canvas/worker — cursor 10801 stale-cite cleanup

Cursor review 10801 (PR #2828) — 6 stale-ratification cites cleaned to
the Q1-α / 9-variant ratified state:

Canvas (PR #2828):
- L13-14 front matter: Field<T>/Rational "no order" → carries compare
  (Director ratified Q1-α via existing Field.compare; line ref :287→:294)
- §6 L216 variant count: "10 post-Q2-Y" → "9 post-Q2-Y" (matches §5 L153
  and Q2-Y disposition; PolynomialCost.degree promotion is not a new
  variant)
- §6 algebra bullets: Q1-c OrderedField.add/compare → Field.add/compare
  on Rational + rational_max lens-local helper (Q1-α)
- §12 Q1 Mgr-rec: stale "c — OrderedField" replaced with full ratified
  Q1-α/Q2-Y/Q3/Q4/Q5/§8 disposition block as audit trail
- §13 reference list: Field<T> "no order" + Q1-c cite → Q1-α via compare

Worker brief:
- §7 phase E receipt: "10 variant count" / "All 10 variant names" → 9
- §10 STOP #3: "Q1-c re-declaration target" → "Q1-α refinement target"
- §14 out-of-scope: "Q1-c lazy migration" → Q1-α (Field unchanged)
- §15 PR body template: "Companion substrate (Q1-c)" → (Q1-α)
- §11 anti-patterns: duplicate #8 numbering fixed → renumber to 1-10
- §16 reference: feedback_strict_mirror Q1-c → Q1-α discipline

INVARIANTS P2 single-authority restored across both briefs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 canvas — fix §10 Mgr-derived duplicate #8 numbering

Per claude/claude-opus-4-7 review 10819 cosmetic note: Mgr-derived
anti-patterns had 7,8,8 → renumber to 8,9,10 (continuing from
Director-enumerated 1-7). Matches the §11 worker brief enumeration.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 worker — fix Phase E sample-test multiplicative absorption

Codex REQUEST_CHANGES review 10837: worker brief §7 line 225 sample test
asserted ExpCost(2,n) · PolyCost(d) collapses to ExpCost(2,n), which
contradicts §6 algebra + anti-pattern #9 (multiplicative cross-class
absorption is unsound; only ProductCost composite is correct).

Fix-forward: corrected sample to assert ProductCost composite under
multiplication; added the additive-sound sibling test (ExpCost + PolyCost
DOES absorb to ExpCost) so both directions of the SUM-sound vs
PRODUCT-unsound asymmetry are receipt-tested.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 canvas — codex 10852 two contradictions in dispatch artifact

Codex REQUEST_CHANGES review 10852 — both findings load-bearing:

1. §5 L172 FactorialCost rule: "FactorialCost(v) + anything = FactorialCost(v)"
   contradicted worker brief's per-variant rules (preserve composites for
   UnknownCost + cross-variable FactorialCost(w)). Expanded canvas table
   to match worker:
   - Same-variable Tier-1-below: absorb to FactorialCost(v)
   - Cross-variable FactorialCost(w): SumCost composite
   - + UnknownCost: SumCost composite (conservative-top, never absorbed)
   - + SumCost/ProductCost composites: distribute and re-fold per §6
   Mirrors operator BLOCKING #5 fix to worker brief (commit adb8417).

2. §5.1 L183 n log n shape: "ProductCost([LinearCost(n), LogCost(n)])"
   reintroduced the LinearCost variant dissolved by ratified Q2-Y.
   Corrected to "ProductCost([PolynomialCost { var: n, degree: 1 },
   LogCost(n)])" — post-Q2-Y collapse via PolynomialCost(degree=1).

INVARIANTS P2 single-authority restored across canvas + worker for both
fold rules. Anti-pattern §11 #10 (LinearCost-consumer paths preserved)
no longer self-violated by the canvas guidance.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 worker — reconcile authority chain (codex 48328e4)

Codex BLOCKING review sha 48328e4: worker brief frontmatter / authority
chain / §9 ledger update / §15 PR body template cited the pre-Q1-α
ratification msg_d86a5987 alone, without msg_676ad4e7 (Q1-α supersession)
reconciliation. The substantive carrier + algebra fixes were clean but
the authority chain leaked the superseded shape.

Fix-forward: every load-bearing authority cite (frontmatter, §0 status,
§2 inputs ratification line, §4 cite-in-comment-block, §9 row-#105 ledger
update text, §13 PR body cite list, §15 PR template, §16 reference) now
cites the **composite ratification**:

  PM msg_a055c38b relaying Director msg_d86a5987 (Q2-Q5 + §8 base)
  RECONCILED BY Director msg_676ad4e7 (Q1-α supersedes prior Q1-c)

Worker dispatches on this composite — not the pre-Q1-α msg_d86a5987 alone.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — Director scope-extension msg_2c1bfb0e (signed Rational)

Director RATIFIED scope-extension on PR #2828 (msg_2c1bfb0e via PM
msg_e5ed6db8 2026-05-13) per operator directive: PolynomialCost.degree
admits signed Rational (arbitrary roots + inverse/decay coverage), no
where-refinement. Q6 dominance ordering + Q7 SymbolicCost preserves full
expression both ratified; new anti-pattern #11 forbidding parallel
InverseCost/ReciprocalCost variants.

Canvas (PR #2828) updates:
- §1 PROMOTE: PolynomialCost.degree = signed Rational (no refinement);
  subsumes negative degrees for asymptotic-decay
- §4 Q2-Y candidate: drop "where degree > 0"; plain Rational
- §6 refinement-carriers: PositiveRational DROPPED (struck-through with
  Director cite); ExponentialBase + PolyLogExponent unchanged
- NEW §6.1 Q6 asymptotic-dominance ordering verbatim Director conjecture
  (reverse-sign-convention via Field.compare; Q1-α authority)
- NEW §6.2 Q7 SymbolicCost preserves full expression; Big-O is derived
  operation (dominant_term / asymptotic_class)
- §10 anti-pattern #11: no parallel InverseCost/ReciprocalCost when
  carrier-extension dissolves question
- §12 ratifications Q6 + Q7 added; Practice 4 GREEN per Director
  pre-emption

Worker brief updates:
- §1 PROMOTE: signed Rational, no refinement
- §5.0 PositiveRational refinement DROPPED with struck-through comment
- §5.1 PolynomialCost.degree: Rational (Q6 signed)
- NEW §6.0 Q7 canonical-form preservation: SymbolicCost preserves all
  terms; canonicalize ≠ dominant_term; mixed-sign canonicalization test
- NEW §6.1 Q6 dominance rule encoded via Field.compare reverse-sign
- §6.2 same-variable algebra fold rules header
- §11 anti-pattern #11 mirrored
- §16 Director msg_2c1bfb0e reference added

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — purge stale PositiveRational refs (cursor 10886)

Cursor APPROVE_WITH_COMMENTS review 10886: post-Q6 scope-extension
(243fd63), several PositiveRational / degree≤0 refinement references
remained in canvas STOP-SIGNAL prose + worker brief verbatim STOP block,
"zero new authority" line, hard-stop directive, STOP condition #4,
anti-pattern #7, and §13 verification axis listing. Worker could follow
the verbatim STOP/anti-pattern text and encode wrong carrier shape
relative to ratified Q6/Q2-Y signed-Rational.

Fix-forward:
- Canvas §6 STOP-SIGNAL prose: PolynomialCost { degree: PositiveRational } → { degree: Rational } (signed per Q6)
- Canvas §10 anti-pattern #7: drop degree≤0/PositiveRational requirement on PolynomialCost; explicit exclusion citing Q6
- Worker §4 verbatim STOP block: same PolynomialCost.degree text fix
- Worker §5.0 "ZERO new authority": drop PositiveRational from refinement list; note PolynomialCost.degree plain signed
- Worker §5.0 hard-stop directive: drop PositiveRational; add Q6 carve-out note
- Worker §10 STOP #4 variant collision: drop PositiveRational from de-dup list; add anti-pattern-#7-fires note
- Worker §11 anti-pattern #7: degree≤0 dropped; explicit PolynomialCost.degree exclusion per Q6
- Worker §13 verification axis: PositiveRational removed from refinement-carriers test list

INVARIANTS P1/P2 single-authority restored across both briefs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — STOP-SIGNAL line range :60-72 → :69-72

Cursor REQUEST_CHANGES 10904: brief cited STOP-SIGNAL as :60-72 across
7 surfaces but the live file has STOP at :69-72 and Pattern 3/4
dissolution receipt at :49-67. A literal Phase B "replace :60-72" would
delete part of the dissolution receipt — INVARIANTS P1 (dispatch prose
must ground in identifiable file facts) + P2 (single edit locus).

Fix-forward:
- Canvas L10 / L46 / L325 STOP-cite: :60-72 → :69-72
- Worker L42 / L90 (Phase B replace) / L261 / L350 / L373: :60-72 → :69-72
- Worker §4 Phase B: explicit DO-NOT-TOUCH callout on :49-67 dissolution
  receipt; replacement is surgical 4-line STOP block only

Brief is now internally consistent with canvas:204 ("Current
src/v3/std/algebra.dag:69-72") which was already correct.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 worker — drop stale gt_zero extension from Phase A list

Cursor APPROVE_WITH_COMMENTS 10920: §5.0 KNOWN_PREDICATES extension list
still required extending gt_zero's allowed_carriers to Rational, but
PositiveRational was dropped in the Q6 scope-extension (243fd63) —
no in-scope refinement uses gt_zero on Rational anymore. Conflicting
dispatch vs the comment block above.

Fix-forward: Phase A list now has only the gt_one addition (genuinely
required for PolyLogExponent = Rational where gt_one). Explicit
parenthetical: gt_zero extension NOT required; range allowed_carriers
already includes Int for ExponentialBase. Only gt_one is new.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — Q6 zero-degree collision + Q7 worker semantics + AP count

Codex BLOCKING review 4bd0cb5 — 2 BLOCKING + 1 non-blocking:

1. Q6 carrier admits degree=0 colliding with ConstantCost (n^0 ≡ 1):
   Fix-forward: keep ratified plain signed Rational carrier; add explicit
   canonicalize-fold rule canvas §6.1 + worker §6 algebra:
   `canonicalize(PolyCost(_, 0)) ⇒ ConstantCost(1)`. Same dissolution
   discipline class as Q2-Y LinearCost ≡ PolyCost(d=1) collapse. Single
   authority for "value=1 constant" via ConstantCost, not parallel via
   PolyCost(_, 0).

2. Q7 output-semantics drift between canvas + worker §14:
   Fix-forward: worker §14 reframed — symbolic_cost_of returns EXACT
   canonical SymbolicCost (Q7 contract change, not backwards-compatible
   reduction). Big-O is derived via dominant_term projection. Legacy
   single-term consumers MUST wrap with dominant_term; canonical-form
   change is expected and ratified.

3. Anti-pattern off-by-one (non-blocking): worker §11 enumerated 11
   items but header + §12 + §13 + §15 PR template said 10. Fix-forward:
   updated all 4 cite-list surfaces to 11 (7 Director-enumerated + 4
   Mgr-derived).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — Q6 Option B Practice-2 carrier refinement (msg_b80bcaa8)

Director RATIFIED Option B on Q6 zero-degree Practice-2 tension via
msg_b80bcaa8 (relayed by PM msg_9d248cbd 2026-05-13). Practice-2
carrier-level `where nonzero` refinement preferred over Practice-4
canonicalize-fold dissolution; sign-admission intent preserved.

Director-distilled discipline rule (NEW, load-bearing):
> Same-variant redundancy → Practice-4 collapse (Q2-Y LinearCost ≡
> PolyCost(d=1)). Cross-variant redundancy → Practice-2 carrier
> refinement (PolyCost(d=0) ≡ ConstantCost(1)). Type-level state-space
> tightening beats API-level normalization when redundant state crosses
> variant boundaries.

Canvas + worker fix-forward:
- §1 PROMOTE / §3 Q2-Y candidate / §6 STOP-SIGNAL / §6.1 dissolution
  text: `Rational` → `Rational where nonzero` (sign-admission via msg_2c1bfb0e
  preserved; only degree=0 excluded)
- Canvas §6.1: reframed from canonicalize-fold to carrier-level
  refinement; Practice-2 vs Practice-4 disambiguation rule encoded
- Worker §5 Phase A KNOWN_PREDICATES list: add `nonzero` predicate
  (allowed_carriers: Rational; arg_shape: Bare); now 2 new predicates
  (gt_one + nonzero), not 1
- Worker §5 "ZERO new authority" line: cite cross-variant vs
  same-variant rule
- Worker §6 algebra table: canonicalize-fold rule REMOVED (type prevents
  construction); multiplicative cancellation rule split into d1+d2≠0
  and d1+d2=0 cases (=0 maps to ConstantCost(1) directly without
  PolyCost(d=0) intermediate which is type-rejected)
- Worker §7 bootstrap ratchet: type-rejection negative test added
  (PolyCost(_, Rational(0)) must be structurally rejected; ±n admits)
- §11 anti-pattern #12 (new, Director-added): forbid canonicalize-fold
  for cross-variant redundancy when carrier refinement available
- AP cite-list counts: 11 → 12 across §11 header / §12 / §13 / §15

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 canvas — reconcile Q2-Y refinement + variant arithmetic

Cursor APPROVE_WITH_COMMENTS 10980 — 2 internal-consistency findings:

1. Q2-Y parenthetical "no where refinement" contradicted the snippet
   directly above showing `where nonzero` (post msg_b80bcaa8 Option B).
   Reconciled: explicit "no positivity / gt_zero refinement" framing
   per Director msg_2c1bfb0e sign-admission intent, AND explicit
   acknowledgment that `where nonzero` IS present per msg_b80bcaa8
   Practice-2 carrier-level Option B (sign-orthogonal, excludes only 0).

2. Q2-Y Pros bullet "11 → 10 net" contradicted §4 closing "**9** net
   under Q2-Y". Reconciled: corrected to "7 → 9 net" matching §1
   ratified scope (+3 new variants -1 collapsed = +3 net over existing
   7) and §4 closing reconciliation pointer.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — codex 77088ff non-blocking wording hygiene

Codex no-blocking + 2 non-blocking improvements (77088ff review):

- worker L156: "no such refinement" → "no positivity refinement, but
  DOES carry where nonzero" (clarifies sign-admission vs zero-exclusion
  distinction for downstream readers).
- canvas L285: §10 anti-pattern header "7 Director + 3 Mgr-derived"
  → "7 Director + 5 Mgr-derived; 12 total" (matches actual 12-item
  list per worker §11 cite-list).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(r3): gate #105 — named NonZeroRational alias (codex worker:167)

Codex BLOCKING worker:167: inline `Rational where nonzero` in struct
field types is unsupported by HEAD parser/lowerer — `where` refinements
attach only to type aliases / parameters (precedent
`type PositiveInt = Nat where gt_zero` at dsl/std/integer.dag:181).
Inline use would require unsupported substrate syntax instead of
making illegal degree=0 unrepresentable through a proper named
refinement carrier.

Fix-forward: introduce `type NonZeroRational = Rational where nonzero`
at the type-alias layer (alongside existing
`PolyLogExponent = Rational where gt_one` +
`ExponentialBase = Int where range(min: 2)`). PolynomialCost.degree
field type references the named alias: `degree: NonZeroRational`.

Updates across both briefs:
- All `degree: Rational where nonzero` → `degree: NonZeroRational`
  (5 canvas occurrences + 10 worker occurrences)
- Worker §5.0 dag block: NonZeroRational alias declaration added with
  rationale comment citing codex worker:167 + HEAD parser constraint
- Canvas §6 refinement-carriers list: NonZeroRational row added with
  named-alias note
- Worker §5.0 HARD STOP directive: NonZeroRational added to the
  hard-stop list (named alias, not fresh record); HEAD parser
  constraint cited
- Worker §10 STOP #4 variant-collision list: NonZeroRational added
- Worker §5.0 P1/P2 narrative: clarified "DOES carry NonZeroRational
  named-alias" framing
- Worker §7 bootstrap ratchet test: type-rejection test asserts both
  the type-alias declaration AND the degree=0 rejection at carrier
  level
- Worker §13 verification axis: NonZeroRational added to refinement-
  carriers test list

INVARIANTS P2 + Practice 2 carrier-level illegal-states-unrepresentable
satisfied via named alias (P5 / parser-supported substrate syntax).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 canvas — fix §6 'no refinement' stale text (codex canvas:218)

Canvas §6 closing paragraph still said "PolynomialCost.degree intentionally
has no refinement" — pre-msg_b80bcaa8 framing that contradicts the
NonZeroRational alias declared 3 lines above + ratified by msg_b80bcaa8.

Fix-forward: reframe as "no positivity refinement, but DOES carry
NonZeroRational named alias for zero-exclusion". Sign-admission
preserved (msg_2c1bfb0e); zero-exclusion enforced (msg_b80bcaa8).
Also added explicit reference to degree=0 alongside exponent≤1 / base≤1
in the structurally-unrepresentable set.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(r3): gate #105 canvas — STOP-SIGNAL Tier-2 cite msg_ad5e934d → msg_d86a5987 (cursor 11087)

Cursor APPROVE_WITH_COMMENTS 11087: canvas §6 STOP-SIGNAL cited
msg_ad5e934d for Tier-2 R4-deferral, but the worker brief §4 verbatim
STOP block cited msg_d86a5987 for the same sentence. msg_ad5e934d was
the original Path A Tier-1 ratification; the §8 Tier-2-deferral
disposition was ratified in msg_d86a5987 (per composite-ratification
text already used elsewhere in worker §0/§2/§9/§13/§15). Canvas
STOP-SIGNAL aligned to msg_d86a5987 for single-authority trace.

INVARIANTS P2 single authoritative trace restored.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
Wire canvas §5 inventory check and ci_uses_affected_set_selection integration
tests into the merge-blocking ci job so Actions shows named consumers for
affected-set selection hygiene. Clarify v3 job comment: Layer 1 vs Layer 2
(Slice 5 / PR #2713 runner) per worker brief §1 and canvas §5–§7.

Regenerate dsl/gunbc/ci_github_actions_workflow.dag from ci.yml.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request May 14, 2026
Wire canvas §5 inventory check and ci_uses_affected_set_selection integration
tests into the merge-blocking ci job so Actions shows named consumers for
affected-set selection hygiene. Clarify v3 job comment: Layer 1 vs Layer 2
(Slice 5 / PR #2713 runner) per worker brief §1 and canvas §5–§7.

Regenerate dsl/gunbc/ci_github_actions_workflow.dag from ci.yml.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request May 14, 2026
Codex blocking review: canvas §7 / Slice-5 runner must wire PR #2713 receipts;
this PR only ships pure gate-id expansion + CiBinaryShimAffectedSetReceipt as a
gate-id seed adapter for tests/future glue. Fix bogus §1.4 cite; point at
§§1.1–4 for end-state NodeRef+metadata join (runner-owned).

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request May 14, 2026
…-set lens output in BinaryShim CI selection (ci_uses_affected_set_selection gate) per Verification brief refresh PR #3018 (#3033)

* WIP: R3 Gap 7 T-WAD Slice 7 affected-set CI integration — consume affected-se

* WIP: R3 Gap 7 T-WAD Slice 7 affected-set CI integration — consume affected-se

* WIP: R3 Gap 7 T-WAD Slice 7 affected-set CI integration — consume affected-se

* WIP: R3 Gap 7 T-WAD Slice 7 affected-set CI integration — consume affected-se

* WIP: R3 Gap 7 T-WAD Slice 7 affected-set CI integration — consume affected-se

* WIP: R3 Gap 7 T-WAD Slice 7 affected-set CI integration — consume affected-se

* WIP: R3 Gap 7 T-WAD Slice 7 affected-set CI integration — consume affected-se

* WIP: R3 Gap 7 T-WAD Slice 7 affected-set CI integration — consume affected-se

* WIP: R3 Gap 7 T-WAD Slice 7 affected-set CI integration — consume affected-se

* WIP: R3 Gap 7 T-WAD Slice 7 affected-set CI integration — consume affected-se

* WIP: R3 Gap 7 T-WAD Slice 7 affected-set CI integration — consume affected-se

* WIP: R3 Gap 7 T-WAD Slice 7 affected-set CI integration — consume affected-se

* WIP: R3 Gap 7 T-WAD Slice 7 affected-set CI integration — consume affected-se

* WIP: R3 Gap 7 T-WAD Slice 7 affected-set CI integration — consume affected-se

* WIP: R3 Gap 7 T-WAD Slice 7 affected-set CI integration — consume affected-se

* WIP: R3 Gap 7 T-WAD Slice 7 affected-set CI integration — consume affected-se

* WIP: R3 Gap 7 T-WAD Slice 7 affected-set CI integration — consume affected-se

* ci: add explicit gate #103 steps (path ratchet + Layer 1 tests)

Wire canvas §5 inventory check and ci_uses_affected_set_selection integration
tests into the merge-blocking ci job so Actions shows named consumers for
affected-set selection hygiene. Clarify v3 job comment: Layer 1 vs Layer 2
(Slice 5 / PR #2713 runner) per worker brief §1 and canvas §5–§7.

Regenerate dsl/gunbc/ci_github_actions_workflow.dag from ci.yml.

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(ci-wad): pin linked timing-lens eval regression on merged carrier

Extract eval_demo_ci_modeled_timing_dimension_report so success and failure
paths share wiring. The CI-modeled workflow test now exercises the linked
gunbc.ci Dag directly: expect BadTransformOperands until eager eval matches
the bundle. Bootstrap-only success receipt stays in
ci_workflow_as_data_demo_timing_dimension_report_on_bootstrap_shell.

Addresses codex REQUEST_CHANGES on #3033 (TESTING.md behavior/interface match).

Co-authored-by: Cursor <cursoragent@cursor.com>

* chore: drop unused gate-57 CI timing fixture; cite optional payload alias

Remove r3_gate57_ci_workflow_timing_lens_carrier.dag (superseded by in-test
concat of ci_github_actions_workflow.dag + ci.dag). Document value↔_0
surface/lowering pairing in lower.rs per docs/v3-spec.md Scenario 6 so
GitHub Actions record rewrites stay traceable.

Co-authored-by: Cursor <cursoragent@cursor.com>

* refactor(eval): single authority for callable-not-arrow BadTransform reason

Introduce `evaluator::BAD_TRANSFORM_CALLABLE_TARGET_NOT_ARROW_REASON` for the
E6-G0c fail-closed path, the evaluator unit test, and the gate-57 linked-carrier
timing-lens integration pin (avoids triplicating the same `reason` literal).

Co-authored-by: Cursor <cursoragent@cursor.com>

* chore: apply rustfmt (evaluator test imports)

Fixes cargo fmt --all --check on CI (BAD_TRANSFORM constant import line break).

Co-authored-by: Cursor <cursoragent@cursor.com>

* refactor(ci): single manifest for gate #103 workflow path-regex fingerprints

Add scripts/workflow-path-regex-forbidden-substrings.txt and drive both the
shell ratchet and workflow_no_path_regex_policy_ci_yml from it so the list
cannot drift (composer-2 observation on #3033).

Co-authored-by: Cursor <cursoragent@cursor.com>

* ci: run workflow_no_path_regex policy in Gate #103 integration step

composer-2 (11486): extend the merge-blocking ci job step so Actions names
both ci_uses_affected_set_selection and workflow_no_path_regex_policy_ci_yml;
second cargo test reuses the warm integration binary. Regenerate
ci_github_actions_workflow.dag from ci.yml.

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(ci): scan all GitHub workflow files for gate #103 fingerprints

Align workflow_no_path_regex_policy_ci_yml with check-workflow-path-regex-inventory.sh
scope (composer-2 11510): every .github/workflows/*.yml|.yaml gets the shared
forbidden-substrings manifest check, not only ci.yml.

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(ci): enumerate workflows via git ls-files like path-regex ratchet

Match check-workflow-path-regex-inventory.sh tracked-file set so local
untracked workflow edits cannot diverge from the shell gate (composer-2 11529).

Co-authored-by: Cursor <cursoragent@cursor.com>

* refactor(lower): name sum-payload surface vs lowered field pairing once

Centralize optional/sum record `value`/`_0` pairing for lowering (claude 11542);
single module-level constants instead of duplicated literals.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: R3 Gap 7 T-WAD Slice 7 affected-set CI integration — consume affected-se

* docs(lower): pin Some/None reserved-constructor intent for optional wrap

Claude-opus-4-7 review: optional_some_none_surface_form matches Call/VariantRecord
targets by spelling; document that this follows language optional disj syntax
(Scenario 6), not arbitrary callables.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: R3 Gap 7 T-WAD Slice 7 affected-set CI integration — consume affected-se

* docs(gunbc-ci): scope gate-103 to Layer 1; drop canvas §1.4 overclaim

Codex blocking review: canvas §7 / Slice-5 runner must wire PR #2713 receipts;
this PR only ships pure gate-id expansion + CiBinaryShimAffectedSetReceipt as a
gate-id seed adapter for tests/future glue. Fix bogus §1.4 cite; point at
§§1.1–4 for end-state NodeRef+metadata join (runner-owned).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: R3 Gap 7 T-WAD Slice 7 affected-set CI integration — consume affected-se

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant