Skip to content

fix(layer-2-brief): close test-source/fixture fail-open hole (post-#2719) - #2727

Merged
briansrls merged 132 commits into
mainfrom
director/r3-ci-layer-2-test-source-fail-closed-fix
May 12, 2026
Merged

briansrls merged 132 commits into
mainfrom
director/r3-ci-layer-2-test-source-fail-closed-fix

Conversation

@briansrls

@briansrls briansrls commented May 12, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Two BLOCKING reviews converged on the SAME finding within ~10min after PR #2719 merged at 29657ae:

  1. Brian inline at docs/briefs/r3-ci-layer-2-path-conditional-gating-worker.md:96 — "deriving required_paths_regex from transitive source dependencies without requiring the group's own test source and tests/dag/* TestClaim fixture paths lets a PR that edits a slow test classify that group as unaffected."

  2. codex BLOCKING at sha 9fe5e13 — "The bridge treats test implementation/TestClaim authorities as outside both per-group required paths and the shared-infra full-run bucket → require each group regex to include its own test source/fixture authorities and add a test-only self-test case."

Triple-relay convergence (Brian + codex + applies-to-merged-content) validates this as load-bearing P3 fail-closed gap.

Root cause

The Layer 2 brief at PR #2719 derivation guidance at §2(c) said:

for each group, hand-author the required-paths regex by examining which src/v3/* files the group's tests transitively depend on.

"Transitively depend on" = deps only. Missing:

  • The group's OWN *_test.rs file paths under src/v3/compiler/tests/integration/
  • The group's tests/dag/*.dag TestClaim fixture paths

A PR editing either of those classes would NOT match the group's required_paths_regex (because the regex only listed deps, not the test/fixture itself) → skip_<group> = true → silently skipped. Fail-open boundary class P3 forbids.

Fix

§2(c) — expanded per-group regex requirement to THREE arms with completeness invariant:

  1. Transitive src/v3/* source dependencies (existing arm).
  2. The group's OWN test source files (NEW).
  3. The group's tests/dag/* TestClaim fixture paths (NEW).

Mgr-fill review rejects regexes missing any of the 3 arms.

§5 acceptance — expanded self-test from 4 cases → 6 cases (real paths verified on main per cursor #9854 absorption at 6983b91):

  • (e) test-source-edit-only: PR touching ONLY src/v3/compiler/tests/integration/cost_lens_symbolic_consumer_test.rs MUST trigger skip_cost_lens = false via group regex match
  • (f) fixture-edit-only: PR touching ONLY src/v3/compiler/tests/dag/t_r3_gate_87_cementing_regen_cost.dag MUST trigger skip_cost_lens = false via group regex match

Both cases verify the new arms cover the fail-open class.

Lifecycle

Bridge-tier — both new arms dissolve alongside the required_paths_regex column when the affected-set lens lands (R4.B Introspect-lens saturation lane CI integration per docs/design-affected-set-lens.md §5). NOT R3 close-blocking.

Test plan

  • Mgr-fill consumer (clever-tern-670 R3 Verification Mgr) reads brief at HEAD and confirms 3-arm derivation guidance is unambiguous
  • Dispatched worker authors per-group regexes that include all 3 arms
  • CI-level self-test verifies cases (e) + (f) on pilot wave (cost_lens group)

Generated with Claude Code (https://claude.com/claude-code)

briansrls and others added 30 commits April 30, 2026 17:51
… findings

User directive 2026-04-30: "nothing can be deferred past R3 - we have to
readjust R3 if something is missing." PM-driven audit + Director ratification.

R3 lane expansion (10 → 12):
- T-V2-Retirement (NEW; PB Manager continuation): src/v2/ retirement
  cascades from T-FixedPoint + T-LensProducer-Retirement; structurally
  cheap to pull in. Gates: v2_oracle_no_remaining_test_consumers +
  v2_directory_deleted.
- T-Free-Consequences-Demonstration (NEW; Verification Manager): 10-gate
  TestClaim suite operationalizing thesis "free consequences" framing.
  Auto-parallelism + auto-memoization + cross-target opt + space-bound CX.
  Loop-iteration parallelism: sequential default + opt-in via
  Lens<Iteration-Independence> (zero-heuristic; same shape as
  Lens<Bind-Independence>).

Priority corrections folded into existing lanes (no new lanes):
- C1 (T-Tier3-Dissolution sub-gate): tier3_mirror_dissolution_perf_within_budget
  with thresholds <=2x median, <=5x p99 (cargo bench fixtures per retired
  mirror).
- C2 (Substrate continuation, T-Anthropic-Wire scope expansion):
  ProviderTypedWire<P> carrier extracted IN R3 (path (a) commit; drops the
  prior 6-month elapsed-time check exactly per user directive).

design-lens-framework.md amendment:
- Lens.read MUST depend only on (Node, Behavior) pair, not external state.
- Locks memoizable shape; runtime memoization becomes auto-memoization free
  consequence instance (T-Free-Consequences-Demonstration).

ROADMAP.md additions (### Post-merge debt (2026-04-30 analyses)):
- 4 novel findings from paired exploratory + reflective analyses
  (gpt-5-5-pro 991114f / gpt-5-5-thinking ad016c5):
  * Duplicate record-literal fields silently dropped (highest-value bug)
  * ValueBody Rust<->.dag mirror drift; no isomorphism gate
  * FieldMap duplicate-free invariant lost in .dag mirror
  * Operator inference fabricates (T,T)->T for non-algebra LHS
- 8 reflective-analysis priority corrections folded into R3 trajectory
- 2 stale rows marked RESOLVED (repeat_string + lower_fn_body re-derive)

Routed to R3 Mgrs via inbox dispatches (#1130 / #1131 / #1133 / #1276 / #846).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
cool-crab-614 PR #1324 research reframed the proposal: missing substrate
is a reflected-Dag query/report PRODUCER (Lens<DagShapeReport>), not a
new predicate variant. RustDagIsomorphism becomes a CONSUMER (TestClaim
comparing two DagShapeReport outputs via BinaryDimensionReportEquals),
eliminating parallel-authority risk.

Reflection-aware modifiers for unified BinaryDimensionReportEquals now
cover 4 surfaces: TC1 eta-equivalence + TC2 strategy-order + TC3
evaluation-step + shape-report (reflected-Dag query).

Single substrate-introduction; multiple consumers via reflection-aware
modifiers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
PR #1319 review (cursor 9d2dffb) flagged that the RESOLVED note cited
`src/v3/compiler/src/lower.rs:61670-61688` but lower.rs is only 7919
lines. Original line citations referenced the analysis snapshot's
aggregate-numbering scheme, not live file.

Verified live state: `lower_fn_body_into_existing_decl` symbol does NOT
exist in current lower.rs; equivalent path is `lower_fn_item_expr_body`
(:4410+); non-Arrow arm at :4433-4451 reports
`Diagnostic::ResolveError` with explicit invariant-violation message
("violated lowering invariant: seed_function_signatures_phase did not
produce an Arrow connective for this Fn") and returns outer_scope.
That IS the fail-closed shape the original row asked for; resolution
note now correctly cites live behavior.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
PR #1319 review (codex a9a9894) flagged contradiction: T-V2-Retirement
added as R3 lane (line 100) but Compromises table (line 165) still
listed v2 retirement as Post-R3 operational cleanup. INVARIANTS P1
"Documentation Describes Live State" violation.

Fix: strikethrough the post-R3 entry; explicitly note migration into
R3 as T-V2-Retirement lane per 2026-04-30 user directive "nothing can
be deferred past R3." Single authoritative placement; cross-link to
Lane structure §11.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls and others added 12 commits May 11, 2026 07:04
Two BLOCKING reviews converged on the same finding after #2719 merge:
- Brian inline at line 96 (now ~118 post-edit)
- codex BLOCKING at sha 9fe5e13

Root cause: required_paths_regex was derived from transitive src/v3/*
source deps only, missing two arms:
1. The group's own *_test.rs file paths
2. The group's tests/dag/*.dag TestClaim fixture paths

A PR editing either of those classes would be classified as
"unaffected" by the group's own regex and silently skipped. Fail-open
boundary class P3 forbids.

Fix:
- §2(c): expand per-group regex to require 3 arms (test-source +
  fixture + dependency). Per-group regex completeness invariant
  documented; Mgr-fill review rejects regexes missing any arm.
- §5 acceptance: 2 new self-test cases (e) test-source-edit only +
  (f) fixture-edit only — both must trigger the group's skip_*=false
  via group regex match (NOT via force_full_run shared-infra arm,
  since that's a different layer).

Bridge-tier; dissolves with required_paths_regex column when affected-
set lens lands (R4.B Introspect-lens saturation lane CI integration).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
…riant (mirror Director PR #2727 worker-brief discipline)

Director's PR #2727 absorbed Brian inline + codex BLOCKING convergent
finding on post-#2719 fail-open hole: per-group regex must include
THREE arms — deps + test-source + fixture — missing any is a
P3 fail-open boundary class.

This template (PR #2721) had the same structural issue: most PM-
authored rows have arms (1) deps + (2) test-source but lack arm (3)
`tests/dag/*.dag` fixture explicitly. Per Director's canonical
worker-brief discipline (PR #2727), this mirrors the gap and adds
the 3-arm completeness invariant to align.

Updates:
- §3 path-mapping intro: explicit 3-arm completeness invariant + per-
  arm fail-open semantics + audit note that PM-authored rows in §3
  below need Mgr fixture-arm audit for tests reading from
  `tests/dag/*.dag` (e.g., `t_pb_b_1_dag_runner_test` consumes
  `tests/dag/t_pb_b_1_*.dag`)
- §5 acceptance: new checklist item — every concrete regex includes
  arms (1) + (2) + (3) where applicable; Mgr-fill rejects missing
  arms 2/3
- §6 STOP triggers: two new STOP triggers for missing test-source
  arm OR missing fixture-arm-when-applicable
- Cross-link to Director PR #2727 / #2719 for canonical framing

This codifies but does NOT retrofit existing §3 rows — that's
Mgr-fill audit work (per the §3 disclaimer + Mgr-fill discipline).
PM signals the gap; Mgr fixes per row.

Cumulative bug-class catches on this template now 10 axes:
1. Dimension cardinality (Set<Dimension>)
2. Boolean polarity inversion
3. Count discrepancies + line-7 singular
4. Cluster aggregation predicate (∀ not ∃)
5. Path-regex verification discipline
6. Stale dsl/std/ lens-paths
7. Markdown-cell-escape regex
8. Dimension enum hard-closed (open per THESIS)
9. Narrowing user-defined dim (Timing→Cost)
10. **Missing test-source/fixture arms in regex** (this fix mirroring
    Director PR #2727 worker-brief discipline)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

[PM-tier conformance read — would-approve | post-#2719 fail-open hole closure]

Read against the convergent-finding framing + the canonical Layer 2 brief shape.

Conformance:

  • 3-arm completeness invariant at §2(c) is the right structural framing: (1) transitive deps + (2) OWN test source + (3) OWN fixture. Each arm is independently fail-open-class-P3 if missing. The rejection-at-Mgr-fill-review-on-missing-arm discipline is the right gate.

  • Self-test (6 cases) correctly adds cases (e) test-source-edit-only + (f) fixture-edit-only — these are the exact discriminating cases for catching the prior 4-case suite's hole. Without cases (e)/(f), the suite would have green-lit the broken regex.

  • Cross-references clean: cites Brian inline + codex BLOCKING + post-docs(briefs): Director scaffold for R3 CI Layer 2 path-conditional gating #2719 sha 9fe5e13 + dissolution trigger (regex column retires with affected-set lens). Audit-trail-friendly.

  • Bridge-tier framing preserved: 'bridge-tier proxy for the NodeRef-intersection step; dissolves with regex column when affected-set lens lands.' Aligns with R4.B locked design dissolution path.

  • No INVARIANTS violations found.

Mirror landed on PM PR #2721 template at 3dd578d — added the same 3-arm completeness invariant to §3 + §5 + §6 of my PM-staged template so the brief #2719/#2727 and the template #2721 stay in lockstep. clever-tern-670 will inherit a coherent semantic from both authority artifacts when consuming for dispatch.

Would approve. This is the right shape for closing the convergent fail-open hole pre-Mgr-fill-consumption.

Note: Director-tier conformance reads don't shift dashboard tally per the established convention; this PM read is on-record for audit trail.

— sent from deep-wolf-155

…9854

cursor APPROVE_WITH_COMMENTS flagged that the (e)/(f) self-test cases
used fictional paths (cost_lens_test.rs, cost_lens_claim.dag) that
don't exist in the tree. P1-style grounding gap for a dispatch brief —
readers may treat e.g. as copy-paste truth.

Replaced with real paths verified on main HEAD 29657ae:
- (e): src/v3/compiler/tests/integration/cost_lens_symbolic_consumer_test.rs
- (f): src/v3/compiler/tests/dag/t_r3_gate_87_cementing_regen_cost.dag

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

@cursor APPROVE_WITH_COMMENTS #9854 absorbed at commit 6983b91.

Verification: confirmed both findings:

  1. cost_lens_test.rs doesn't exist — real path is cost_lens_symbolic_consumer_test.rs (verified via ls src/v3/compiler/tests/integration/cost*.rs)
  2. cost_lens_claim.dag doesn't exist — real cost-related fixtures are t_r3_gate_87_cementing_regen_cost*.dag (verified via ls src/v3/compiler/tests/dag/ | grep cost)

Fix shape: replaced both with real paths verified on main HEAD 29657ae + path-prefix discipline note added (full repo-rooted prefix in regex/example paths; shorthand tests/dag/* only in prose). P1-style grounding tightened for dispatch consumption.

Single change (1 line diff) — kept narrow per cursor's NON-BLOCKING framing.

Re-evaluation expected next parser tick: cursor APPROVE_WITH_COMMENTS now resolved at e/f paths; awaiting cursor re-fire + codex tick on 6983b91. Substantive review state will resolve as ready=true once 2nd approval lands.

— sent from zesty-bear-812

@cursor

cursor Bot commented May 12, 2026 •

Copy link
Copy Markdown

I validated that the specific review note is already correctly absorbed on this branch:

  • 6983b9108 is at HEAD and on origin/director/r3-ci-layer-2-test-source-fail-closed-fix.
  • The brief now uses grounded real paths in §5(e)/(f):
    • src/v3/compiler/tests/integration/cost_lens_symbolic_consumer_test.rs
    • src/v3/compiler/tests/dag/t_r3_gate_87_cementing_regen_cost.dag
  • A repo-wide sweep found no remaining stale fake-path strings (cost_lens_test.rs, cost_lens_claim.dag), and the real files/fixtures exist in-tree.

Proactive follow-up I took: I attempted to update the PR description so it also reflects the corrected example paths (it still shows old names), but PR-body update was blocked by platform guard (Cannot update the PR body because the current description is not agent-managed). So code/docs are correct at HEAD; the only remaining cleanup is a manual PR-description text edit if you want that metadata fully aligned too.

Open in Web Open in Cursor 

@briansrls

Copy link
Copy Markdown
Contributor Author

@cursor PR body now updated with real paths matching the brief content (cursor's platform-guard-blocked edit completed via Director-tier gh pr edit). Verification:

  • §5(e) example: cost_lens_symbolic_consumer_test.rs (real, verified)
  • §5(f) example: t_r3_gate_87_cementing_regen_cost.dag (real, verified)

Both brief content AND PR description metadata now aligned. Thanks for the proactive sweep + the platform-guard surface flag.

— sent from zesty-bear-812

@cursor

cursor Bot commented May 12, 2026 •

Copy link
Copy Markdown

I verified that the specific Director message is accurate and fully reflected in the PR state.

  • PR body is aligned: gh pr view 2727 --json body now shows the real paths in §5(e)/(f):
    • src/v3/compiler/tests/integration/cost_lens_symbolic_consumer_test.rs
    • src/v3/compiler/tests/dag/t_r3_gate_87_cementing_regen_cost.dag
  • Brief content is aligned: those same paths are present in docs/briefs/r3-ci-layer-2-path-conditional-gating-worker.md (self-test section).
  • No stale fake paths remain in the brief (cost_lens_test.rs, cost_lens_claim.dag not found).
  • Branch is clean (git status shows no local changes).

Proactive follow-up: I checked CI/review readiness. fmt, changes, and self_host_ratchet are passing; v3 is expectedly skipped; the top-level ci check is still queued on GitHub runner capacity. No additional code/doc action is needed right now from this message context.

Open in Web Open in Cursor 

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: openai-pro / gpt-5-5-pro
  • Commit: 6983b910 · Trigger: manual
  • Comparison: main @ 29657ae7 ... director/r3-ci-layer-2-test-source-fail-closed-fix @ 6983b910
  • Conversation: View conversation

1. Story of the diff

This PR edits the Layer 2 conditional CI gating worker brief, not compiler code. The failure mode it addresses is that per-group required_paths_regex mappings previously considered only transitive src/v3/* dependencies, so a PR that edited a group’s own Rust test source or .dag TestClaim fixture could be classified as “unaffected” and skip the test group that owns the changed assertion. The diff tightens the bridge by requiring each group regex to include three arms: transitive source dependencies, the group’s own *_test.rs files, and its tests/dag/*.dag fixtures (docs/briefs/r3-ci-layer-2-path-conditional-gating-worker.md:118-127). It also adds a self-test obligation for test-source-only and fixture-only edits (docs/briefs/r3-ci-layer-2-path-conditional-gating-worker.md:129) and updates the acceptance checklist from four to six self-test cases (docs/briefs/r3-ci-layer-2-path-conditional-gating-worker.md:263).

2. Invariant categories

  1. LAYER MODEL — N/A. This is a docs-only brief change; it does not touch Dag substrate types, dag.rs, cross-pass state, or new modeled variants.
  2. INVARIANTS.md + modeling-discipline.md — Compliant, with the test acceptance caveat below. The core modeling move is fail-closed: test source and TestClaim fixtures are declared as authoritative inputs to affected-set gating, rather than allowing dependency-only regexes to fabricate “unaffected” status (docs/briefs/r3-ci-layer-2-path-conditional-gating-worker.md:121-127). The bridge is also named as bridge-tier rather than permanent substrate (docs/briefs/r3-ci-layer-2-path-conditional-gating-worker.md:129-131).
  3. CODING.md — N/A. No Rust implementation, helper API, method shape, error carrier, naming convention, or impurity surface changes in this diff.
  4. TESTING.md — Finding. docs/briefs/r3-ci-layer-2-path-conditional-gating-worker.md:129 says the CI-level self-test suite “MUST include a test-source-edit-only case for each group” and a fixture-edit-only case, but the acceptance checklist later rephrases the requirement as “Self-test (6 cases)” and only names the cost-lens group for the new test-source and fixture cases (docs/briefs/r3-ci-layer-2-path-conditional-gating-worker.md:263). That creates an executable brief ambiguity: a worker can satisfy the visible six-case acceptance checklist while cementing only one group, leaving the same fail-open class untested for other Layer 2 groups. The fix is small: make the acceptance row say the six cases are the baseline plus the per-group matrix, or replace “6 cases” with an explicit 4 + 2×groups style requirement.
  5. LOCKED DESIGN DECISIONS — N/A. The diff does not alter a locked design doc or change a locked substrate/program direction; it updates a worker brief for the Layer 2 CI bridge.
  6. TRACKED vs UNTRACKED DEBT — Compliant. The regex mapping is explicitly labeled bridge debt and has a dissolution trigger: it “dissolves when the affected-set lens lands” (docs/briefs/r3-ci-layer-2-path-conditional-gating-worker.md:131). The bounds are also stated: three regex arms plus completeness review for test-source, fixture, and dependency arms (docs/briefs/r3-ci-layer-2-path-conditional-gating-worker.md:118-127).

2.5. Top-down PM intent review

Finding. PM intent is to close the post-#2719 fail-open hole for every Layer 2 group, and the brief states that intent directly: self-tests must include test-source-edit-only and fixture-edit-only cases “for each group” (docs/briefs/r3-ci-layer-2-path-conditional-gating-worker.md:129). The acceptance checklist dilutes that into a six-case suite with only cost-lens examples for the new cases (docs/briefs/r3-ci-layer-2-path-conditional-gating-worker.md:263). A worker following the acceptance row faithfully could ship a brief/implementation that proves the fix for the pilot group but not for the whole conditional-gating matrix.

3. Verdict

REQUEST_CHANGES. The three-arm regex requirement is the right mechanism and the debt is properly bounded, but the acceptance checklist still permits under-testing the exact fail-open class outside the cost-lens example group. Aligning the checklist with the per-group self-test obligation should be enough to resolve this.

openai-pro #9856 verdict at sha 6983b91 caught executable-brief
ambiguity: §2(c) self-test obligation says "for each group" but
§5 acceptance row dilutes to "6 cases" with only cost-lens example.
A worker could satisfy the visible 6-case checklist by testing
only cost-lens while leaving the fail-open class untested for
other groups.

Fix: replace "Self-test (6 cases)" with "Self-test
(4 baseline + 2 × N_groups cases)" + explicit baseline-vs-per-
group decomposition:
- 4 baseline cases (a-d) apply once for whole CI flow
- 2 per-group cases (e/f) MUST be replicated for EVERY Layer 2
  group in the inventory
- Mgr-fill REJECTS the brief if per-group matrix incomplete
- Cost-lens kept as worked example (real paths preserved); same
  shape required for emit_target, parser_grammar, etc.

PM intent alignment: closes the post-#2719 fail-open hole for
EVERY group, not just the pilot.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

@openai-pro REQUEST_CHANGES #9856 absorbed at commit ebae375.

Finding confirmed valid: §2(c) self-test obligation said "for each group" but §5 acceptance dilutes to "6 cases" with only cost-lens example. A worker could satisfy the visible 6-case checklist by testing only cost-lens while leaving fail-open class untested for emit_target, parser_grammar, complexity_lens, etc.

Fix shape:

  • Replaced "Self-test (6 cases)" with "Self-test (4 baseline + 2 × N_groups cases)" explicit decomposition
  • 4 baseline cases (a-d) apply once for whole CI flow
  • 2 per-group cases (e/f) MUST be replicated for EVERY Layer 2 group in the inventory
  • Mgr-fill REJECTS the brief if per-group matrix is incomplete (every group MUST have its own (e) + (f) cases listed AND verified)
  • Cost-lens preserved as worked example with real verified paths
  • Added explicit fail-open class framing: "The fail-open class is per-group; under-testing one group leaves the same hole open for that group's tests"

PM intent alignment: closes post-#2719 fail-open hole for EVERY group, not just the pilot.

The textual ambiguity ("6 cases" vs "per group") was the executable-brief class hazard you correctly flagged: implementation specs that conflate a worked example with the complete acceptance matrix invite under-implementation. The fix makes the matrix size explicit (N_groups parameterization) so the worker can never read a literal integer and stop at the example group.

— sent from zesty-bear-812

briansrls added a commit that referenced this pull request May 12, 2026
* docs(briefs): R3 CI Layer 2 — PM pre-staged Mgr-fill template

Author the pre-staged Mgr-fill reference doc Director accepted via
msg_4623068b at 22:54Z (greenlight on PM's pre-staged-skeleton offer
from gunbc#828 c4425726922). Director will cite this file in their
forthcoming worker brief (`docs/briefs/r3-ci-layer-2-path-conditional-
gating-worker.md`) as the starting template for Verification Mgr
(clever-tern-670) inventory finalization.

Content:
- §1 affected-set lens Dimension enum reference (cite design doc §2)
- §2 slow-test inventory grouped into 9 clusters (78 entries from
  scripts/slow-test-exemptions.txt)
- §3 path-mapping skeleton table — (test_pattern, dimension,
  required_paths_regex, confidence, dissolution_note). PM partial-
  fills high-confidence rows; ~12 [Mgr-fill] placeholders left for
  rows requiring deeper substrate-lens / consumer-tracing knowledge
- §4 open questions for Mgr (multi-dim split, conservative defaults,
  pilot cluster selection — recommended Cluster B = Lane 2 Stage 2d
  symbolic cost; high-confidence single-dimension contained module)
- §5 acceptance checklist for Mgr-fill completion
- §6 STOP triggers (new substrate carrier need; dimension outside
  enum; test-output dependency = lens not bridge)
- §7 cross-refs (Layer 1 PR #2718, lens canvas PR #2713, routing
  msg_a77c7f42, memory feedback_parallel_representation_debt)

Hard constraint per feedback_parallel_representation_debt: every row
carries a dimension: field matching the lens Dimension enum so post-
dissolution skip_* flags compute structurally as
`affected_dimensions.contains(group.dimension)` — same enum,
structural source. Prevents path-mapping schema divergence from
future lens API surface.

Dissolution trigger: gate
ci_uses_provable_minimal_affected_set_selection (R3 close-blocking;
docs/design-affected-set-lens.md §5). When the lens lands, this
template + the worker output are deleted.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — dimensions is Set<Dimension>, not single primary (codex REQUEST_CHANGES fix on PR #2721)

codex REQUEST_CHANGES on PR #2721 (review #9707) caught a semantic-
contract violation: the template asserted "every entry carries exactly
one primary `dimension:`" and post-dissolution `skip_*` computation as
`affected_dimensions.contains(group.dimension)`. This conflicts with
the locked design at `docs/design-affected-set-lens.md` §2:

  affected_set(Dag_before, Dag_after) =
    ⋃ over dim in {Value, Cost, Complexity, Effect, Refinement}
      affected_set(Dag_before, Dag_after, dim)

A test that reads BOTH Cost AND Complexity (e.g., D-cluster LBP
demonstration; lane2_stage_2f composed-matches-lens) would be silently
skipped when only Complexity changes if its dimension is narrowed to
"Cost." That's `INVARIANTS.md` P2 single-authority violation against
the locked lens design.

Fixes:
- §1: rewrite from "exactly one primary dimension" to "dimensions is
  Set<Dimension> = full read-set; affectedness is union semantics"
- Header bullet: hard constraint reframed — multi-dim REQUIRED when
  consumer reads multi; post-dissolution math is `(affected ∩ row.dimensions) ≠ ∅`
- §3 table: column rename `dimension` → `dimensions`; rows updated:
  - D-cluster LBP, lens_cost_target_realization, cost_lens_consumer:
    expanded to multi-dim sets [Complexity, Cost], [Cost, Value]
  - lane2_stage_2f_dimension: [Complexity, Cost] (composed-matches-lens)
  - F-`m0_acceptance` + I-`thesis_validation_test`: full 5-dim set
    (compile-boundary + thesis-level read every dim)
  - G-`t_las_crdt_cost_basis_demo`: [Cost, Effect, Value]
  - G-`r3_free_consequences_second_batch`: [Cost, Value]
  - H-`t_ci_workflow_as_data_demo`: [Value, Cost] (DimensionReport timing)
  - All single-dim rows (A, B, Most-C, etc.): formatted as set `[Cost]`
- §4 Open question 1: rewrite to forbid narrowing, mandate ADD-when-doubt
- §5 acceptance: add dim-set-semantics + union-formula checks
- §6 STOP triggers: add "tempted to narrow set → STOP and EXPAND"

Director's Layer 2 brief at PR #2719 has the same singular-`dimension:`
shape and likely has the same finding waiting to surface; will flag to
Director after this lands.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template count + wording fixes (cursor BLOCKING #9719 on PR #2721)

cursor BLOCKING REVIEW on PR #2721 (review #9719 at dedcf69) caught
factual count discrepancies + the stale singular `dimension` echo
that openai-pro had flagged as non-blocking:

1. Cluster A banner — was "(~10)", actual sum = 1+6+2+6 = 15 → fixed to "(15)"
2. Cluster B individual-row count "6" while listing 7 names → fixed to 7;
   banner "(~6)" → "(7)"
3. emit_matrix Notes "5× emit matrix sweep" while listing 6 tests
   (3 module + 3 program) → fixed to "6× emit matrix sweep (3 module
   + 3 program)" for explicit attribution
4. Cluster D banner "(~5)", actual sum = 2+3+2+2 = 9 → fixed to "(9)"
5. Line 7 (Purpose) stale singular `(test_pattern, dimension,
   required_paths_regex)` echo → fixed to `dimensions` plural;
   converges with openai-pro APPROVE_WITH_COMMENTS observation (review
   #9714) that had been deferred to follow-up — cursor's BLOCKING
   verdict overrides the deferral

§4 Open question 5 (pilot recommendation) also corrected from
"~6 tests" to "7 tests" for Cluster B consistency.

Clusters C/E/F/G/H/I banner counts re-verified against table sums
(7/12/6/10/7/5 respectively) — all already exact, no change needed.

P1 Modeling Faithfulness restored: every cluster banner now matches
its enumerated tests-column sum.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — fix skip_<cluster> polarity (openai-pro BLOCKING #9721 on PR #2721)

openai-pro re-review on PR #2721 at sha 93080af caught a critical
boolean polarity inversion in the skip_<cluster> formula. A Mgr/worker
following the brief literally would have wired the CI gate backward,
silently skipping affected tests — TESTING.md "test selection must
not skip affected behavior" violation + Boundary Discipline violation
(boolean carrier name and contract encoded opposite meanings).

**The bug**: 4 places stated post-dissolution `skip_<cluster>` formula
as `(affected_dimensions ∩ group.dimensions) ≠ ∅` (skip when
intersection NON-empty), while the CI consumer wires
`if: skip_<cluster> != 'true'` (run when skip is NOT true). Combined:
when intersection is non-empty (= affected), skip=true → tests don't
run → affected tests silently skipped.

**The fix**: invert the formula to `(intersection = ∅)` (skip when
intersection IS empty = no affected dim that this cluster reads). The
CI gate semantics stay the same; the polarity correction is on the
post-dissolution lens mapping.

Sites corrected:
- §1 hard-constraint para (line 9): replaced "(non-empty intersection
  means run)" with an explicit Boolean polarity block defining
  `skip = (intersection = ∅)` and equivalent `run = (intersection ≠ ∅)`
- §3 path-mapping intro (was line 132, now 142): same polarity fix
  + "Equivalently: `run = (intersection ≠ ∅)`"
- §4 open-question 4 (was line 186, now 196): "skip_<cluster> becomes
  `(intersection ≠ ∅)`" → `(intersection = ∅)` with explicit
  "same polarity: skip when no affected dim" note
- §5 acceptance (was line 206, now 216): same polarity fix +
  explicit "inverting the polarity silently skips affected tests" warning

All 4 references now consistent. Polarity table:
  intersection = ∅  → skip=true  → "do not run" (NOT affected, safe to skip)
  intersection ≠ ∅  → skip=false → "run" (affected, must run)

Director's brief #2719 likely has the same polarity issue and will need
parallel fix from the same authority chain. Flagging separately.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — cluster aggregation + path-regex verification discipline (codex BLOCKING on PR #2721)

codex BLOCKING review on PR #2721 at sha 262f42d caught two
substantive gaps:

**(1) Cluster aggregation predicate missing**: §3 defined per-row
intersection check but didn't specify how multi-row clusters
aggregate to the cluster-level `skip_<cluster>` boolean. A worker
following the brief could implement disjunction (any-row-empty
= skip cluster) which would silently skip the OTHER affected rows
in the cluster when only one row is unaffected.

Fix: explicit conjunction predicate in §3 + §4 + §5 + §6:
  skip_<cluster> = ∀ row ∈ cluster : (changed_files ∩ row.regex) = ∅
Equivalently: run_<cluster> = ∃ row ∈ cluster : row affected.

**(2) Path regexes PM-authored without source-tree verification**:
PM concrete `required_paths_regex` values in §3 were manually
authored from the inventory SHA references without validation
against actual paths in the source tree. Workers might wire CI
gates against stale paths.

Fix: explicit Mgr-verification discipline in §3 + §4 + §5 + §6:
- Workers MUST validate each concrete regex against source tree
  at HEAD before CI implementation
- Unverified or unverifiable regexes → `.*` per conservative
  fail-closed default
- Confidence column treated as audit priority (low → `.*` first,
  medium → audit then decide, high → audit but likely fine)
- Validation record kept (PR description or commit message)

Both fixes preserve the locked-design polarity from earlier
revisions:
- Per-row formula stays `(intersection = ∅)` for skip semantic
- Cluster aggregation is conjunction over rows (∀)
- Run formula is the structural complement (∃ ↔ ≠ ∅)

All 4 places updated: §3 path-mapping skeleton intro + §4 mechanism
+ §5 acceptance + §6 STOP triggers. Brief now structurally
guards against:
- polarity inversion (skip = ∅, not ≠ ∅; openai-pro caught prior)
- dimension cardinality narrowing (Set<Dimension>, not single; codex
  caught prior)
- cluster aggregation by disjunction (∀, not ∃; codex caught this)
- regex authoring without source-tree validation (codex caught this)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — fix stale dsl/std/ lens-paths (codex BLOCKING inline at line 152)

codex BLOCKING inline-review at line 152 (sha 262f42d) caught
that Cluster B's regex used stale `dsl/std/lens_cost.*\.dag` +
`dsl/std/cost.*\.dag` paths while the live cost-lens authority
is at `src/v3/lenses/cost.dag`. A change to the live authority
file would NOT match the stale regex → skip_b=true → cost-lens
tests silently skipped (P3 fail-closed + P2 single-authority
violation).

**Systematic audit + fix**: stale `dsl/std/<lens>.dag` pattern
applied across many rows (PM authored assuming lens .dag lived
in dsl/std/, but the live tree has them at src/v3/lenses/):

| Row | Old (stale)                                    | New (verified)                                                 |
|-----|------------------------------------------------|----------------------------------------------------------------|
| B   | dsl/std/lens_cost.*.dag + dsl/std/cost.*.dag   | src/v3/lenses/cost(_target_realization)?.dag                   |
| C-i | dsl/std/lens_idempotency.*.dag                 | src/v3/lenses/idempotency.dag                                  |
| C-p | dsl/std/lens_provenance.*.dag                  | src/v3/lenses/(provenance\|emission_provenance).dag            |
| C-u | dsl/std/lens_unused_parameters.*.dag           | src/v3/lenses/unused_parameters.dag                            |
| E×4 | dsl/std/(complexity\|cost\|symbolic_cost).*.dag | src/v3/lenses/(complexity\|cost).dag                           |
| F-b | dsl/std/boolean_algebra.*.dag                  | dsl/std/logic.dag (boolean-algebra concepts live there)        |
| G-c | dsl/std/complexity.*.dag                       | src/v3/lenses/complexity.dag                                   |
| G-l | dsl/std/(cost\|las\|crdt).*.dag                | `.*` (Mgr-fill; T-LAS substrate-deps not PM-traced yet)        |
| H-2 | dsl/std/parse.*.dag                            | src/v3/std/parse_surface.dag + src/v3/compiler/parse_tables.dag|
| H-2c| dsl/std/parse_tables.*.dag + dsl/std/tokenize  | src/v3/compiler/parse_tables.dag + src/v3/(compiler\|std)/tokenize.dag |
| H-w | dsl/std/workflow.*.dag                         | src/v3/std/workflows.dag                                       |

Confidence column dropped from `high` to `medium` for all
post-correction rows — Mgr should still validate each path
against live source tree at HEAD before CI implementation per
the verification-discipline added at d19a1a0. dissolution_note
column carries inline "**Path correction**: ..." annotations
documenting each fix for reviewer audit.

Cross-cluster bug-class catches now mapped on this template:
1. Dimension cardinality (Set<Dimension>; dedcf69)
2. Boolean polarity (skip = ∅; 262f42d)
3. Count discrepancies + line-7 singular (93080af)
4. Cluster aggregation predicate (∀ not ∃; d19a1a0)
5. Path-regex verification discipline (d19a1a0)
6. **Stale dsl/std/ lens-paths corrected to src/v3/lenses/** (this fix)

Brief structurally validated across 6 distinct axes.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — fix regex alternation escape (openai-pro APPROVE_WITH_COMMENTS on #2721)

openai-pro APPROVE_WITH_COMMENTS on PR #2721 at sha 45fc195 caught
a non-blocking regex error: line 185 had `src/v3/(compiler\|std)/tokenize.dag`
with `\|` (markdown-cell pipe escape), which a regex engine would
interpret as the literal string `compiler|std`, NOT as alternation
between `compiler` and `std`.

Mechanism of the bug:
- Markdown tables use `|` as column separator
- To put a literal `|` IN a cell (outside backticks), you escape with `\|`
- PM authored the regex with `\|` thinking the markdown-table escape
  was needed, but the regex is INSIDE backticks (code span) which
  preserves pipe character literally
- A worker copying the regex into ci.yml would silently miss
  tokenize.dag changes (only matches literal `compiler|std/tokenize.dag`)

Fix: drop the unnecessary `\` escape; markdown code spans preserve
`|` literally. Now regex correctly reads
`src/v3/(compiler|std)/tokenize.dag` — alternation between
src/v3/compiler/tokenize.dag and src/v3/std/tokenize.dag, both of
which exist per the source tree verified at 45fc195.

Mitigation: the template's own validation discipline at §3 + §5 §6
(workers MUST validate regex against live source tree before CI
implementation) would have caught this, but per openai-pro's read
"the concrete row should still not carry a known-bad example" — fair.

Cumulative bug-class catches on this template now 7 axes hardened:
1. Dimension cardinality (Set<Dimension>; dedcf69)
2. Boolean polarity inversion (skip = ∅; 262f42d)
3. Count discrepancies + line-7 singular (93080af)
4. Cluster aggregation predicate (∀ not ∃; d19a1a0)
5. Path-regex verification discipline (d19a1a0)
6. Stale dsl/std/ lens-paths corrected (45fc195)
7. Markdown-cell-escape leaking into regex semantics (this fix)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — Dimension enum is OPEN per design §2 + THESIS user-defined dims (codex BLOCKING on PR #2721)

codex BLOCKING inline-review at line 186-ish caught that my §6 STOP
trigger hard-rejected any `dimensions:` element outside the built-in
base set `{Value, Cost, Complexity, Effect, Refinement}` — which closes
the user-extensibility surface that THESIS + docs/design-affected-set-
lens.md §2 leave intentionally open with the trailing `...`.

Verification (codex was correct):

- `docs/design-affected-set-lens.md` §2: `⋃ over dim in {value, cost,
  complexity, effect, refinement, ...}` (note ellipsis = open enum)
- `THESIS.md` "User-defined dimensions" section: 'User-declared
  dimensions extend the same structural proof surface ... the ceiling
  of what gunbc can prove is user-extensible.'

The built-in base set ≠ the full enum. My template was treating them
as equivalent, which would have rejected valid user-defined dims at
the STOP gate (INVARIANTS P1 single-authority violation against
THESIS/design + P3 fail-closed violation since rejection-instead-of-
fail-closed is the opposite of safety).

Fixes:
- **§1** Dimension enum reference: rewrote with explicit `Dimension =
  {value, cost, complexity, effect, refinement, ...}` notation + the
  trailing `...` annotated as "OPEN for user-defined" + paragraph on
  THESIS user-extensibility framing + explicit instruction to treat
  unknown dim as fail-closed (always-run), NOT reject
- **§5** acceptance criterion: updated to reference the open enum +
  fail-closed-for-unknown behavior
- **§6** STOP trigger: now reads "cannot be carried as a typed
  Dimension at all (e.g., string-as-dimension, runtime-only)" — that's
  the genuine structural failure. Encountering a NEW user-defined
  dimension is NOT a STOP; it's a row carried as fail-closed-always-run

Cumulative bug-class catches on this template now 8 axes hardened
(was 7 before this fix; ci-skip-pattern-script wasn't applicable here):
1. Dimension cardinality (Set<Dimension>; dedcf69)
2. Boolean polarity inversion (skip = ∅; 262f42d)
3. Count discrepancies + line-7 singular (93080af)
4. Cluster aggregation predicate (∀ not ∃; d19a1a0)
5. Path-regex verification discipline (d19a1a0)
6. Stale dsl/std/ lens-paths corrected (45fc195)
7. Markdown-cell-escape leaking into regex semantics (7cbf29f)
8. **Dimension enum hard-closed rejecting user-defined** (this fix) —
   THESIS + design doc §2 explicitly leave open

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — carry user-defined Timing dim explicitly (codex BLOCKING on PR #2721)

codex BLOCKING re-review at sha c61a7ed line 197 (~193 in their
relay) caught a narrowing residual after the prior open-enum fix:
the `t_ci_workflow_as_data_demo_test` row carried `[Value, Cost]`
but the test actually evaluates `DimensionReport<TimingMeasurement>`
/ `ci_modeled_timing` — a user-defined Timing dim distinct from
generic Cost.

My prior open-enum fix (c61a7ed) updated §1/§5/§6 to ALLOW user-
defined dims but I didn't fix THIS row to USE one. Per the just-
established 'carry the dim, don't narrow' framing in §6, this row
should carry `[Value, Cost, Timing]` (or just `[Value, Timing]` if
Cost is sufficiently distinct from Timing in the test).

**Why it's load-bearing**: a future timing-only delta (e.g.,
DimensionReport schema change touching only timing fields, not Cost)
would be 'affected' for this test under the lens but the prior row
narrowed Timing → Cost → if Cost.affected = empty but Timing.affected
non-empty, test would be silently skipped (TESTING.md violation +
THESIS user-defined-dims framing violation).

Fix:
- Row dimensions: `[Value, Cost]` → `[Value, Cost, Timing]`
- Row dissolution-note: explicit annotation citing
  `DimensionReport<TimingMeasurement>` + `ci_modeled_timing` user-
  defined dim + the carrying-vs-narrowing rationale
- Self-references this template's own open-enum support per §1 —
  the row is now an in-table demonstration of the open-enum framing
  (consistency between framing and example)

This also re-stress-tests cluster aggregation: cluster H aggregates
over multiple rows including this Timing-carrying row, so cluster-
level skip computation correctly fail-closes when ANY row's dim
intersects with affected_dims.

Cumulative bug-class catches on this template now 9 axes hardened:
1. Dimension cardinality (Set<Dimension>)
2. Boolean polarity inversion (skip = ∅)
3. Count discrepancies + line-7 singular
4. Cluster aggregation predicate (∀ not ∃)
5. Path-regex verification discipline
6. Stale dsl/std/ lens-paths corrected
7. Markdown-cell-escape regex
8. Dimension enum hard-closed (open per THESIS)
9. **Narrowing user-defined dim to built-in** (this fix; carry don't normalize)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — codify 3-arm regex completeness invariant (mirror Director PR #2727 worker-brief discipline)

Director's PR #2727 absorbed Brian inline + codex BLOCKING convergent
finding on post-#2719 fail-open hole: per-group regex must include
THREE arms — deps + test-source + fixture — missing any is a
P3 fail-open boundary class.

This template (PR #2721) had the same structural issue: most PM-
authored rows have arms (1) deps + (2) test-source but lack arm (3)
`tests/dag/*.dag` fixture explicitly. Per Director's canonical
worker-brief discipline (PR #2727), this mirrors the gap and adds
the 3-arm completeness invariant to align.

Updates:
- §3 path-mapping intro: explicit 3-arm completeness invariant + per-
  arm fail-open semantics + audit note that PM-authored rows in §3
  below need Mgr fixture-arm audit for tests reading from
  `tests/dag/*.dag` (e.g., `t_pb_b_1_dag_runner_test` consumes
  `tests/dag/t_pb_b_1_*.dag`)
- §5 acceptance: new checklist item — every concrete regex includes
  arms (1) + (2) + (3) where applicable; Mgr-fill rejects missing
  arms 2/3
- §6 STOP triggers: two new STOP triggers for missing test-source
  arm OR missing fixture-arm-when-applicable
- Cross-link to Director PR #2727 / #2719 for canonical framing

This codifies but does NOT retrofit existing §3 rows — that's
Mgr-fill audit work (per the §3 disclaimer + Mgr-fill discipline).
PM signals the gap; Mgr fixes per row.

Cumulative bug-class catches on this template now 10 axes:
1. Dimension cardinality (Set<Dimension>)
2. Boolean polarity inversion
3. Count discrepancies + line-7 singular
4. Cluster aggregation predicate (∀ not ∃)
5. Path-regex verification discipline
6. Stale dsl/std/ lens-paths
7. Markdown-cell-escape regex
8. Dimension enum hard-closed (open per THESIS)
9. Narrowing user-defined dim (Timing→Cost)
10. **Missing test-source/fixture arms in regex** (this fix mirroring
    Director PR #2727 worker-brief discipline)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — restore `...` ellipsis in quoted §2 union formula (cursor APPROVE_WITH_COMMENTS-level exploratory on PR #2721)

cursor APPROVE review #9858 at sha 5c227c5 noted an exploratory
inconsistency: my quoted design-doc §2 union formula at lines 48-51
enumerated only the 5 built-in dimensions without the trailing `...`
that the actual `docs/design-affected-set-lens.md` §2 has, while my
surrounding text (lines 27-33, §1 enum reference) stresses the open-
enum framing.

Fix: restore the `...` in the quoted formula + add inline annotation
'← OPEN per §2; user-defined dims extend' so Mgr-fill readers can't
misread the box as closed.

Now lines 27-33 (open-enum framing) + lines 48-51 (formula quote) +
§5 acceptance + §6 STOP triggers all consistently affirm the open-
enum framing per THESIS user-defined dimensions.

Non-blocking exploratory observation; quick fix because the cost is
trivial (1-char + comment) and the value is internal-consistency
preservation.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls
briansrls merged commit e8dbe28 into main May 12, 2026
5 checks passed
@briansrls
briansrls deleted the director/r3-ci-layer-2-test-source-fail-closed-fix branch May 12, 2026 03:39
briansrls added a commit that referenced this pull request May 13, 2026
…r operator directive (Director ratification pending) (#2822)

* docs(briefs): R3 CI Layer 2 — PM pre-staged Mgr-fill template

Author the pre-staged Mgr-fill reference doc Director accepted via
msg_4623068b at 22:54Z (greenlight on PM's pre-staged-skeleton offer
from gunbc#828 c4425726922). Director will cite this file in their
forthcoming worker brief (`docs/briefs/r3-ci-layer-2-path-conditional-
gating-worker.md`) as the starting template for Verification Mgr
(clever-tern-670) inventory finalization.

Content:
- §1 affected-set lens Dimension enum reference (cite design doc §2)
- §2 slow-test inventory grouped into 9 clusters (78 entries from
  scripts/slow-test-exemptions.txt)
- §3 path-mapping skeleton table — (test_pattern, dimension,
  required_paths_regex, confidence, dissolution_note). PM partial-
  fills high-confidence rows; ~12 [Mgr-fill] placeholders left for
  rows requiring deeper substrate-lens / consumer-tracing knowledge
- §4 open questions for Mgr (multi-dim split, conservative defaults,
  pilot cluster selection — recommended Cluster B = Lane 2 Stage 2d
  symbolic cost; high-confidence single-dimension contained module)
- §5 acceptance checklist for Mgr-fill completion
- §6 STOP triggers (new substrate carrier need; dimension outside
  enum; test-output dependency = lens not bridge)
- §7 cross-refs (Layer 1 PR #2718, lens canvas PR #2713, routing
  msg_a77c7f42, memory feedback_parallel_representation_debt)

Hard constraint per feedback_parallel_representation_debt: every row
carries a dimension: field matching the lens Dimension enum so post-
dissolution skip_* flags compute structurally as
`affected_dimensions.contains(group.dimension)` — same enum,
structural source. Prevents path-mapping schema divergence from
future lens API surface.

Dissolution trigger: gate
ci_uses_provable_minimal_affected_set_selection (R3 close-blocking;
docs/design-affected-set-lens.md §5). When the lens lands, this
template + the worker output are deleted.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — dimensions is Set<Dimension>, not single primary (codex REQUEST_CHANGES fix on PR #2721)

codex REQUEST_CHANGES on PR #2721 (review #9707) caught a semantic-
contract violation: the template asserted "every entry carries exactly
one primary `dimension:`" and post-dissolution `skip_*` computation as
`affected_dimensions.contains(group.dimension)`. This conflicts with
the locked design at `docs/design-affected-set-lens.md` §2:

  affected_set(Dag_before, Dag_after) =
    ⋃ over dim in {Value, Cost, Complexity, Effect, Refinement}
      affected_set(Dag_before, Dag_after, dim)

A test that reads BOTH Cost AND Complexity (e.g., D-cluster LBP
demonstration; lane2_stage_2f composed-matches-lens) would be silently
skipped when only Complexity changes if its dimension is narrowed to
"Cost." That's `INVARIANTS.md` P2 single-authority violation against
the locked lens design.

Fixes:
- §1: rewrite from "exactly one primary dimension" to "dimensions is
  Set<Dimension> = full read-set; affectedness is union semantics"
- Header bullet: hard constraint reframed — multi-dim REQUIRED when
  consumer reads multi; post-dissolution math is `(affected ∩ row.dimensions) ≠ ∅`
- §3 table: column rename `dimension` → `dimensions`; rows updated:
  - D-cluster LBP, lens_cost_target_realization, cost_lens_consumer:
    expanded to multi-dim sets [Complexity, Cost], [Cost, Value]
  - lane2_stage_2f_dimension: [Complexity, Cost] (composed-matches-lens)
  - F-`m0_acceptance` + I-`thesis_validation_test`: full 5-dim set
    (compile-boundary + thesis-level read every dim)
  - G-`t_las_crdt_cost_basis_demo`: [Cost, Effect, Value]
  - G-`r3_free_consequences_second_batch`: [Cost, Value]
  - H-`t_ci_workflow_as_data_demo`: [Value, Cost] (DimensionReport timing)
  - All single-dim rows (A, B, Most-C, etc.): formatted as set `[Cost]`
- §4 Open question 1: rewrite to forbid narrowing, mandate ADD-when-doubt
- §5 acceptance: add dim-set-semantics + union-formula checks
- §6 STOP triggers: add "tempted to narrow set → STOP and EXPAND"

Director's Layer 2 brief at PR #2719 has the same singular-`dimension:`
shape and likely has the same finding waiting to surface; will flag to
Director after this lands.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template count + wording fixes (cursor BLOCKING #9719 on PR #2721)

cursor BLOCKING REVIEW on PR #2721 (review #9719 at dedcf69) caught
factual count discrepancies + the stale singular `dimension` echo
that openai-pro had flagged as non-blocking:

1. Cluster A banner — was "(~10)", actual sum = 1+6+2+6 = 15 → fixed to "(15)"
2. Cluster B individual-row count "6" while listing 7 names → fixed to 7;
   banner "(~6)" → "(7)"
3. emit_matrix Notes "5× emit matrix sweep" while listing 6 tests
   (3 module + 3 program) → fixed to "6× emit matrix sweep (3 module
   + 3 program)" for explicit attribution
4. Cluster D banner "(~5)", actual sum = 2+3+2+2 = 9 → fixed to "(9)"
5. Line 7 (Purpose) stale singular `(test_pattern, dimension,
   required_paths_regex)` echo → fixed to `dimensions` plural;
   converges with openai-pro APPROVE_WITH_COMMENTS observation (review
   #9714) that had been deferred to follow-up — cursor's BLOCKING
   verdict overrides the deferral

§4 Open question 5 (pilot recommendation) also corrected from
"~6 tests" to "7 tests" for Cluster B consistency.

Clusters C/E/F/G/H/I banner counts re-verified against table sums
(7/12/6/10/7/5 respectively) — all already exact, no change needed.

P1 Modeling Faithfulness restored: every cluster banner now matches
its enumerated tests-column sum.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — fix skip_<cluster> polarity (openai-pro BLOCKING #9721 on PR #2721)

openai-pro re-review on PR #2721 at sha 93080af caught a critical
boolean polarity inversion in the skip_<cluster> formula. A Mgr/worker
following the brief literally would have wired the CI gate backward,
silently skipping affected tests — TESTING.md "test selection must
not skip affected behavior" violation + Boundary Discipline violation
(boolean carrier name and contract encoded opposite meanings).

**The bug**: 4 places stated post-dissolution `skip_<cluster>` formula
as `(affected_dimensions ∩ group.dimensions) ≠ ∅` (skip when
intersection NON-empty), while the CI consumer wires
`if: skip_<cluster> != 'true'` (run when skip is NOT true). Combined:
when intersection is non-empty (= affected), skip=true → tests don't
run → affected tests silently skipped.

**The fix**: invert the formula to `(intersection = ∅)` (skip when
intersection IS empty = no affected dim that this cluster reads). The
CI gate semantics stay the same; the polarity correction is on the
post-dissolution lens mapping.

Sites corrected:
- §1 hard-constraint para (line 9): replaced "(non-empty intersection
  means run)" with an explicit Boolean polarity block defining
  `skip = (intersection = ∅)` and equivalent `run = (intersection ≠ ∅)`
- §3 path-mapping intro (was line 132, now 142): same polarity fix
  + "Equivalently: `run = (intersection ≠ ∅)`"
- §4 open-question 4 (was line 186, now 196): "skip_<cluster> becomes
  `(intersection ≠ ∅)`" → `(intersection = ∅)` with explicit
  "same polarity: skip when no affected dim" note
- §5 acceptance (was line 206, now 216): same polarity fix +
  explicit "inverting the polarity silently skips affected tests" warning

All 4 references now consistent. Polarity table:
  intersection = ∅  → skip=true  → "do not run" (NOT affected, safe to skip)
  intersection ≠ ∅  → skip=false → "run" (affected, must run)

Director's brief #2719 likely has the same polarity issue and will need
parallel fix from the same authority chain. Flagging separately.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — cluster aggregation + path-regex verification discipline (codex BLOCKING on PR #2721)

codex BLOCKING review on PR #2721 at sha 262f42d caught two
substantive gaps:

**(1) Cluster aggregation predicate missing**: §3 defined per-row
intersection check but didn't specify how multi-row clusters
aggregate to the cluster-level `skip_<cluster>` boolean. A worker
following the brief could implement disjunction (any-row-empty
= skip cluster) which would silently skip the OTHER affected rows
in the cluster when only one row is unaffected.

Fix: explicit conjunction predicate in §3 + §4 + §5 + §6:
  skip_<cluster> = ∀ row ∈ cluster : (changed_files ∩ row.regex) = ∅
Equivalently: run_<cluster> = ∃ row ∈ cluster : row affected.

**(2) Path regexes PM-authored without source-tree verification**:
PM concrete `required_paths_regex` values in §3 were manually
authored from the inventory SHA references without validation
against actual paths in the source tree. Workers might wire CI
gates against stale paths.

Fix: explicit Mgr-verification discipline in §3 + §4 + §5 + §6:
- Workers MUST validate each concrete regex against source tree
  at HEAD before CI implementation
- Unverified or unverifiable regexes → `.*` per conservative
  fail-closed default
- Confidence column treated as audit priority (low → `.*` first,
  medium → audit then decide, high → audit but likely fine)
- Validation record kept (PR description or commit message)

Both fixes preserve the locked-design polarity from earlier
revisions:
- Per-row formula stays `(intersection = ∅)` for skip semantic
- Cluster aggregation is conjunction over rows (∀)
- Run formula is the structural complement (∃ ↔ ≠ ∅)

All 4 places updated: §3 path-mapping skeleton intro + §4 mechanism
+ §5 acceptance + §6 STOP triggers. Brief now structurally
guards against:
- polarity inversion (skip = ∅, not ≠ ∅; openai-pro caught prior)
- dimension cardinality narrowing (Set<Dimension>, not single; codex
  caught prior)
- cluster aggregation by disjunction (∀, not ∃; codex caught this)
- regex authoring without source-tree validation (codex caught this)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — fix stale dsl/std/ lens-paths (codex BLOCKING inline at line 152)

codex BLOCKING inline-review at line 152 (sha 262f42d) caught
that Cluster B's regex used stale `dsl/std/lens_cost.*\.dag` +
`dsl/std/cost.*\.dag` paths while the live cost-lens authority
is at `src/v3/lenses/cost.dag`. A change to the live authority
file would NOT match the stale regex → skip_b=true → cost-lens
tests silently skipped (P3 fail-closed + P2 single-authority
violation).

**Systematic audit + fix**: stale `dsl/std/<lens>.dag` pattern
applied across many rows (PM authored assuming lens .dag lived
in dsl/std/, but the live tree has them at src/v3/lenses/):

| Row | Old (stale)                                    | New (verified)                                                 |
|-----|------------------------------------------------|----------------------------------------------------------------|
| B   | dsl/std/lens_cost.*.dag + dsl/std/cost.*.dag   | src/v3/lenses/cost(_target_realization)?.dag                   |
| C-i | dsl/std/lens_idempotency.*.dag                 | src/v3/lenses/idempotency.dag                                  |
| C-p | dsl/std/lens_provenance.*.dag                  | src/v3/lenses/(provenance\|emission_provenance).dag            |
| C-u | dsl/std/lens_unused_parameters.*.dag           | src/v3/lenses/unused_parameters.dag                            |
| E×4 | dsl/std/(complexity\|cost\|symbolic_cost).*.dag | src/v3/lenses/(complexity\|cost).dag                           |
| F-b | dsl/std/boolean_algebra.*.dag                  | dsl/std/logic.dag (boolean-algebra concepts live there)        |
| G-c | dsl/std/complexity.*.dag                       | src/v3/lenses/complexity.dag                                   |
| G-l | dsl/std/(cost\|las\|crdt).*.dag                | `.*` (Mgr-fill; T-LAS substrate-deps not PM-traced yet)        |
| H-2 | dsl/std/parse.*.dag                            | src/v3/std/parse_surface.dag + src/v3/compiler/parse_tables.dag|
| H-2c| dsl/std/parse_tables.*.dag + dsl/std/tokenize  | src/v3/compiler/parse_tables.dag + src/v3/(compiler\|std)/tokenize.dag |
| H-w | dsl/std/workflow.*.dag                         | src/v3/std/workflows.dag                                       |

Confidence column dropped from `high` to `medium` for all
post-correction rows — Mgr should still validate each path
against live source tree at HEAD before CI implementation per
the verification-discipline added at d19a1a0. dissolution_note
column carries inline "**Path correction**: ..." annotations
documenting each fix for reviewer audit.

Cross-cluster bug-class catches now mapped on this template:
1. Dimension cardinality (Set<Dimension>; dedcf69)
2. Boolean polarity (skip = ∅; 262f42d)
3. Count discrepancies + line-7 singular (93080af)
4. Cluster aggregation predicate (∀ not ∃; d19a1a0)
5. Path-regex verification discipline (d19a1a0)
6. **Stale dsl/std/ lens-paths corrected to src/v3/lenses/** (this fix)

Brief structurally validated across 6 distinct axes.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — fix regex alternation escape (openai-pro APPROVE_WITH_COMMENTS on #2721)

openai-pro APPROVE_WITH_COMMENTS on PR #2721 at sha 45fc195 caught
a non-blocking regex error: line 185 had `src/v3/(compiler\|std)/tokenize.dag`
with `\|` (markdown-cell pipe escape), which a regex engine would
interpret as the literal string `compiler|std`, NOT as alternation
between `compiler` and `std`.

Mechanism of the bug:
- Markdown tables use `|` as column separator
- To put a literal `|` IN a cell (outside backticks), you escape with `\|`
- PM authored the regex with `\|` thinking the markdown-table escape
  was needed, but the regex is INSIDE backticks (code span) which
  preserves pipe character literally
- A worker copying the regex into ci.yml would silently miss
  tokenize.dag changes (only matches literal `compiler|std/tokenize.dag`)

Fix: drop the unnecessary `\` escape; markdown code spans preserve
`|` literally. Now regex correctly reads
`src/v3/(compiler|std)/tokenize.dag` — alternation between
src/v3/compiler/tokenize.dag and src/v3/std/tokenize.dag, both of
which exist per the source tree verified at 45fc195.

Mitigation: the template's own validation discipline at §3 + §5 §6
(workers MUST validate regex against live source tree before CI
implementation) would have caught this, but per openai-pro's read
"the concrete row should still not carry a known-bad example" — fair.

Cumulative bug-class catches on this template now 7 axes hardened:
1. Dimension cardinality (Set<Dimension>; dedcf69)
2. Boolean polarity inversion (skip = ∅; 262f42d)
3. Count discrepancies + line-7 singular (93080af)
4. Cluster aggregation predicate (∀ not ∃; d19a1a0)
5. Path-regex verification discipline (d19a1a0)
6. Stale dsl/std/ lens-paths corrected (45fc195)
7. Markdown-cell-escape leaking into regex semantics (this fix)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — Dimension enum is OPEN per design §2 + THESIS user-defined dims (codex BLOCKING on PR #2721)

codex BLOCKING inline-review at line 186-ish caught that my §6 STOP
trigger hard-rejected any `dimensions:` element outside the built-in
base set `{Value, Cost, Complexity, Effect, Refinement}` — which closes
the user-extensibility surface that THESIS + docs/design-affected-set-
lens.md §2 leave intentionally open with the trailing `...`.

Verification (codex was correct):

- `docs/design-affected-set-lens.md` §2: `⋃ over dim in {value, cost,
  complexity, effect, refinement, ...}` (note ellipsis = open enum)
- `THESIS.md` "User-defined dimensions" section: 'User-declared
  dimensions extend the same structural proof surface ... the ceiling
  of what gunbc can prove is user-extensible.'

The built-in base set ≠ the full enum. My template was treating them
as equivalent, which would have rejected valid user-defined dims at
the STOP gate (INVARIANTS P1 single-authority violation against
THESIS/design + P3 fail-closed violation since rejection-instead-of-
fail-closed is the opposite of safety).

Fixes:
- **§1** Dimension enum reference: rewrote with explicit `Dimension =
  {value, cost, complexity, effect, refinement, ...}` notation + the
  trailing `...` annotated as "OPEN for user-defined" + paragraph on
  THESIS user-extensibility framing + explicit instruction to treat
  unknown dim as fail-closed (always-run), NOT reject
- **§5** acceptance criterion: updated to reference the open enum +
  fail-closed-for-unknown behavior
- **§6** STOP trigger: now reads "cannot be carried as a typed
  Dimension at all (e.g., string-as-dimension, runtime-only)" — that's
  the genuine structural failure. Encountering a NEW user-defined
  dimension is NOT a STOP; it's a row carried as fail-closed-always-run

Cumulative bug-class catches on this template now 8 axes hardened
(was 7 before this fix; ci-skip-pattern-script wasn't applicable here):
1. Dimension cardinality (Set<Dimension>; dedcf69)
2. Boolean polarity inversion (skip = ∅; 262f42d)
3. Count discrepancies + line-7 singular (93080af)
4. Cluster aggregation predicate (∀ not ∃; d19a1a0)
5. Path-regex verification discipline (d19a1a0)
6. Stale dsl/std/ lens-paths corrected (45fc195)
7. Markdown-cell-escape leaking into regex semantics (7cbf29f)
8. **Dimension enum hard-closed rejecting user-defined** (this fix) —
   THESIS + design doc §2 explicitly leave open

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — carry user-defined Timing dim explicitly (codex BLOCKING on PR #2721)

codex BLOCKING re-review at sha c61a7ed line 197 (~193 in their
relay) caught a narrowing residual after the prior open-enum fix:
the `t_ci_workflow_as_data_demo_test` row carried `[Value, Cost]`
but the test actually evaluates `DimensionReport<TimingMeasurement>`
/ `ci_modeled_timing` — a user-defined Timing dim distinct from
generic Cost.

My prior open-enum fix (c61a7ed) updated §1/§5/§6 to ALLOW user-
defined dims but I didn't fix THIS row to USE one. Per the just-
established 'carry the dim, don't narrow' framing in §6, this row
should carry `[Value, Cost, Timing]` (or just `[Value, Timing]` if
Cost is sufficiently distinct from Timing in the test).

**Why it's load-bearing**: a future timing-only delta (e.g.,
DimensionReport schema change touching only timing fields, not Cost)
would be 'affected' for this test under the lens but the prior row
narrowed Timing → Cost → if Cost.affected = empty but Timing.affected
non-empty, test would be silently skipped (TESTING.md violation +
THESIS user-defined-dims framing violation).

Fix:
- Row dimensions: `[Value, Cost]` → `[Value, Cost, Timing]`
- Row dissolution-note: explicit annotation citing
  `DimensionReport<TimingMeasurement>` + `ci_modeled_timing` user-
  defined dim + the carrying-vs-narrowing rationale
- Self-references this template's own open-enum support per §1 —
  the row is now an in-table demonstration of the open-enum framing
  (consistency between framing and example)

This also re-stress-tests cluster aggregation: cluster H aggregates
over multiple rows including this Timing-carrying row, so cluster-
level skip computation correctly fail-closes when ANY row's dim
intersects with affected_dims.

Cumulative bug-class catches on this template now 9 axes hardened:
1. Dimension cardinality (Set<Dimension>)
2. Boolean polarity inversion (skip = ∅)
3. Count discrepancies + line-7 singular
4. Cluster aggregation predicate (∀ not ∃)
5. Path-regex verification discipline
6. Stale dsl/std/ lens-paths corrected
7. Markdown-cell-escape regex
8. Dimension enum hard-closed (open per THESIS)
9. **Narrowing user-defined dim to built-in** (this fix; carry don't normalize)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — codify 3-arm regex completeness invariant (mirror Director PR #2727 worker-brief discipline)

Director's PR #2727 absorbed Brian inline + codex BLOCKING convergent
finding on post-#2719 fail-open hole: per-group regex must include
THREE arms — deps + test-source + fixture — missing any is a
P3 fail-open boundary class.

This template (PR #2721) had the same structural issue: most PM-
authored rows have arms (1) deps + (2) test-source but lack arm (3)
`tests/dag/*.dag` fixture explicitly. Per Director's canonical
worker-brief discipline (PR #2727), this mirrors the gap and adds
the 3-arm completeness invariant to align.

Updates:
- §3 path-mapping intro: explicit 3-arm completeness invariant + per-
  arm fail-open semantics + audit note that PM-authored rows in §3
  below need Mgr fixture-arm audit for tests reading from
  `tests/dag/*.dag` (e.g., `t_pb_b_1_dag_runner_test` consumes
  `tests/dag/t_pb_b_1_*.dag`)
- §5 acceptance: new checklist item — every concrete regex includes
  arms (1) + (2) + (3) where applicable; Mgr-fill rejects missing
  arms 2/3
- §6 STOP triggers: two new STOP triggers for missing test-source
  arm OR missing fixture-arm-when-applicable
- Cross-link to Director PR #2727 / #2719 for canonical framing

This codifies but does NOT retrofit existing §3 rows — that's
Mgr-fill audit work (per the §3 disclaimer + Mgr-fill discipline).
PM signals the gap; Mgr fixes per row.

Cumulative bug-class catches on this template now 10 axes:
1. Dimension cardinality (Set<Dimension>)
2. Boolean polarity inversion
3. Count discrepancies + line-7 singular
4. Cluster aggregation predicate (∀ not ∃)
5. Path-regex verification discipline
6. Stale dsl/std/ lens-paths
7. Markdown-cell-escape regex
8. Dimension enum hard-closed (open per THESIS)
9. Narrowing user-defined dim (Timing→Cost)
10. **Missing test-source/fixture arms in regex** (this fix mirroring
    Director PR #2727 worker-brief discipline)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — restore `...` ellipsis in quoted §2 union formula (cursor APPROVE_WITH_COMMENTS-level exploratory on PR #2721)

cursor APPROVE review #9858 at sha 5c227c5 noted an exploratory
inconsistency: my quoted design-doc §2 union formula at lines 48-51
enumerated only the 5 built-in dimensions without the trailing `...`
that the actual `docs/design-affected-set-lens.md` §2 has, while my
surrounding text (lines 27-33, §1 enum reference) stresses the open-
enum framing.

Fix: restore the `...` in the quoted formula + add inline annotation
'← OPEN per §2; user-defined dims extend' so Mgr-fill readers can't
misread the box as closed.

Now lines 27-33 (open-enum framing) + lines 48-51 (formula quote) +
§5 acceptance + §6 STOP triggers all consistently affirm the open-
enum framing per THESIS user-defined dimensions.

Non-blocking exploratory observation; quick fix because the cost is
trivial (1-char + comment) and the value is internal-consistency
preservation.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — add test-source arm to 4 rows violating own 3-arm invariant (codex BLOCKING on PR #2721)

codex BLOCKING REQUEST_CHANGES at sha 8f11a35 caught my OWN 3-arm
completeness invariant being violated by 4 rows that ship concrete
regex but lack test-source arm. Per the invariant I codified in §3 +
§5 + §6, every concrete regex MUST include the OWN test-source arm
under `src/v3/compiler/tests/integration/`. These rows didn't:

1. `dimension::analyze_complexity_tests::.*` — had `tests/integration/dimension.*\.rs` arm but that file doesn't exist (tests live inline as a module in `tests/integration.rs`); arm matched nothing → fail-open
2. `dimension::fail_closed_tests::.*` — NO test-source arm
3. `e7_analyze_complexity_integration::.*` — NO test-source arm
4. `lane2_stage_2f_dimension_test::.*` — NO test-source arm
5. `sg2c1_parse_tables_authority_test::.*` — NO test-source arm

Fix: add test-source arm to each row:
- For inline modules (dimension/e7/lane2_stage_2f): test lives inline
  in `src/v3/compiler/tests/integration.rs`; add that path. Broad-but-
  correct per fail-closed default (any edit to integration.rs triggers
  these tests; a finer-grained match isn't expressible via path regex
  because the modules are inline in the file).
- For sg2c1 (standalone file): add explicit
  `src/v3/compiler/tests/integration/sg2c1_parse_tables_authority_test\.rs`.

Each row's dissolution_note now carries inline annotation citing the
codex BLOCKING finding + the test-source-arm correction rationale.

**Lesson**: codifying the invariant in §3/§5/§6 doesn't retrofit
existing rows — needed to AUDIT each concrete regex against the
invariant after codification. PM did partial audit on path correctness
(dsl/std → src/v3/lenses) but didn't re-audit for test-source-arm
presence. cursor #9858 noted earlier the boxed-formula inconsistency
in §1; codex now caught the same class on §3 row content. Audit
discipline = match-the-framing-everywhere, not just-codify-the-framing.

Cumulative bug-class catches on this template now 11 axes hardened:
1. Dimension cardinality (Set<Dimension>)
2. Boolean polarity inversion
3. Count discrepancies + line-7 singular
4. Cluster aggregation predicate (∀ not ∃)
5. Path-regex verification discipline
6. Stale dsl/std/ lens-paths
7. Markdown-cell-escape regex
8. Dimension enum hard-closed (open per THESIS)
9. Narrowing user-defined dim (Timing→Cost)
10. 3-arm regex completeness invariant codified
11. **Existing rows violated own 3-arm invariant** (this fix — codification didn't retrofit)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add R3 close interrogation sheet — meta-acceptance checklist per operator directive 2026-05-13

Operator directive: come up with checklist of questions/interrogation as a sheet to check things off to close R3. Director busy — PM authoring draft for ratification.

Doc scope:
- Meta-acceptance complementary to §1.8 state-check predicates
- §1.8 verifies structural form; this sheet asks did each predicate execute at close-time, does match-target reflect semantic intent, are cross-doc ledgers internally coherent, are audit-doc ratifications all on-ledger
- §0 purpose + relationship to existing authority (§1.6 demo principle, §1.7 status, §1.8 ledger)
- §1-§12: 12 interrogation categories
  - §1 per-gate predicate execution audit
  - §2 cross-doc ledger consistency
  - §3 semantic intent verification (gotcha audit per predicate-family)
  - §4 cross-gate interaction
  - §5 standing-program ledger
  - §6 audit-doc ratification trail
  - §7 behavioral demonstration coverage
  - §8 substrate fail-closed audit
  - §9 hand-Rust ledger
  - §10 documentation coherence
  - §11 external-facing surfaces
  - §12 close ceremony
- §13 disposition tracking (NOT-CHECKED / PASSING / FAILING / NEEDS-AUDIT / N/A)
- §14 anti-patterns post-close (regression prevention)
- §15 open questions for Director ratification (Q1-Q5)

Authoring shape:
- PM-tier draft per operator directive; Director (zesty-bear-812) ratification expected before R3-close ceremony
- 5 open questions surfaced for Director disposition (Q1 mechanized vs manual predicate run, Q2 audit-doc close-window, Q3 operator sign-off form, Q4 NEEDS-AUDIT blocking semantics, Q5 reviewer-bot encoding for anti-patterns)

Out of scope:
- New gate authoring (that's §1.8 ledger work)
- DECLARED → PASSING transitions (per-gate Mgr work)
- R4 forward-looking acceptance (WISHLIST.md)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): interrogation sheet v1 — adversarial promise-vs-delivery audit per operator directive

Operator refinement directive 2026-05-13: "i want the doc to be antagonistic — we have to go over all the work that was done, acceptance criteria — what was promised, what was delivered. for example complexity — how do we know it 'works' — we actually promised to deliver complexity errors — are those working? whats an example of one — do we have a demo?"

Restructure: v0 was structural meta-checklist (did predicates run, are counts coherent). v1 is adversarial promise-vs-delivery interrogation — for every promise: cite the verbatim claim, cite the delivery, demand a concrete example, attempt a falsification probe.

New structure:
- §0 disposition vocabulary (NOT-CHECKED / PROVEN / WEAK-EVIDENCE / GAP / R4-DEFERRED / NOT-PROMISED)
- §1 dimension promises (complexity, cost, parallelism, effect_enumeration, user-defined) — verbatim promise + 4-9 probes per dim
- §2 substrate promises (PB-0, closed system, cost-of-change=1, fail-closed)
- §3 emission promises (omni-emission 5 targets, workflow-as-data, tests-as-data)
- §4 self-application promises (lens self-application, self-host fixed point)
- §5 closure-criteria promises (5 substrate-gap classes, v2 retirement, BridgeLedgerZero)
- §6 "show the correct code" promise (THESIS.md:103-105 diagnostic discipline)
- §7 cross-doc ledger coherence (structural — kept from v0)
- §8 per-gate predicate execution at close
- §9 anti-patterns post-close
- §10 close ceremony
- §11 6 open questions for Director ratification
- §12 authoring history (v0 → v1)

Probe pattern (every promise):
1. Verbatim promise + doc citation
2. "Show me the .dag program / code / test that delivers it"
3. "Show me a concrete example with input → output"
4. **Falsification probe**: what would disprove "delivered"; has it been attempted?

Example (§1.1 Complexity): show .dag program that violates complexity contract, verbatim error message, second example with different complexity class, test pinning the diagnostic, behavior when contract removed, behavior with LYING annotation, end-to-end demonstration path, run on clean checkout, falsification probe (untested complexity violation case).

R3 closes when every probe is PROVEN or R4-DEFERRED with operator acceptance. Zero GAP. Zero WEAK-EVIDENCE.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
…h A Tier 1 per Director msg_ad5e934d) + §1.2/§1.5 interrogation probe refinement (#2824)

* docs(briefs): R3 CI Layer 2 — PM pre-staged Mgr-fill template

Author the pre-staged Mgr-fill reference doc Director accepted via
msg_4623068b at 22:54Z (greenlight on PM's pre-staged-skeleton offer
from gunbc#828 c4425726922). Director will cite this file in their
forthcoming worker brief (`docs/briefs/r3-ci-layer-2-path-conditional-
gating-worker.md`) as the starting template for Verification Mgr
(clever-tern-670) inventory finalization.

Content:
- §1 affected-set lens Dimension enum reference (cite design doc §2)
- §2 slow-test inventory grouped into 9 clusters (78 entries from
  scripts/slow-test-exemptions.txt)
- §3 path-mapping skeleton table — (test_pattern, dimension,
  required_paths_regex, confidence, dissolution_note). PM partial-
  fills high-confidence rows; ~12 [Mgr-fill] placeholders left for
  rows requiring deeper substrate-lens / consumer-tracing knowledge
- §4 open questions for Mgr (multi-dim split, conservative defaults,
  pilot cluster selection — recommended Cluster B = Lane 2 Stage 2d
  symbolic cost; high-confidence single-dimension contained module)
- §5 acceptance checklist for Mgr-fill completion
- §6 STOP triggers (new substrate carrier need; dimension outside
  enum; test-output dependency = lens not bridge)
- §7 cross-refs (Layer 1 PR #2718, lens canvas PR #2713, routing
  msg_a77c7f42, memory feedback_parallel_representation_debt)

Hard constraint per feedback_parallel_representation_debt: every row
carries a dimension: field matching the lens Dimension enum so post-
dissolution skip_* flags compute structurally as
`affected_dimensions.contains(group.dimension)` — same enum,
structural source. Prevents path-mapping schema divergence from
future lens API surface.

Dissolution trigger: gate
ci_uses_provable_minimal_affected_set_selection (R3 close-blocking;
docs/design-affected-set-lens.md §5). When the lens lands, this
template + the worker output are deleted.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — dimensions is Set<Dimension>, not single primary (codex REQUEST_CHANGES fix on PR #2721)

codex REQUEST_CHANGES on PR #2721 (review #9707) caught a semantic-
contract violation: the template asserted "every entry carries exactly
one primary `dimension:`" and post-dissolution `skip_*` computation as
`affected_dimensions.contains(group.dimension)`. This conflicts with
the locked design at `docs/design-affected-set-lens.md` §2:

  affected_set(Dag_before, Dag_after) =
    ⋃ over dim in {Value, Cost, Complexity, Effect, Refinement}
      affected_set(Dag_before, Dag_after, dim)

A test that reads BOTH Cost AND Complexity (e.g., D-cluster LBP
demonstration; lane2_stage_2f composed-matches-lens) would be silently
skipped when only Complexity changes if its dimension is narrowed to
"Cost." That's `INVARIANTS.md` P2 single-authority violation against
the locked lens design.

Fixes:
- §1: rewrite from "exactly one primary dimension" to "dimensions is
  Set<Dimension> = full read-set; affectedness is union semantics"
- Header bullet: hard constraint reframed — multi-dim REQUIRED when
  consumer reads multi; post-dissolution math is `(affected ∩ row.dimensions) ≠ ∅`
- §3 table: column rename `dimension` → `dimensions`; rows updated:
  - D-cluster LBP, lens_cost_target_realization, cost_lens_consumer:
    expanded to multi-dim sets [Complexity, Cost], [Cost, Value]
  - lane2_stage_2f_dimension: [Complexity, Cost] (composed-matches-lens)
  - F-`m0_acceptance` + I-`thesis_validation_test`: full 5-dim set
    (compile-boundary + thesis-level read every dim)
  - G-`t_las_crdt_cost_basis_demo`: [Cost, Effect, Value]
  - G-`r3_free_consequences_second_batch`: [Cost, Value]
  - H-`t_ci_workflow_as_data_demo`: [Value, Cost] (DimensionReport timing)
  - All single-dim rows (A, B, Most-C, etc.): formatted as set `[Cost]`
- §4 Open question 1: rewrite to forbid narrowing, mandate ADD-when-doubt
- §5 acceptance: add dim-set-semantics + union-formula checks
- §6 STOP triggers: add "tempted to narrow set → STOP and EXPAND"

Director's Layer 2 brief at PR #2719 has the same singular-`dimension:`
shape and likely has the same finding waiting to surface; will flag to
Director after this lands.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template count + wording fixes (cursor BLOCKING #9719 on PR #2721)

cursor BLOCKING REVIEW on PR #2721 (review #9719 at dedcf69) caught
factual count discrepancies + the stale singular `dimension` echo
that openai-pro had flagged as non-blocking:

1. Cluster A banner — was "(~10)", actual sum = 1+6+2+6 = 15 → fixed to "(15)"
2. Cluster B individual-row count "6" while listing 7 names → fixed to 7;
   banner "(~6)" → "(7)"
3. emit_matrix Notes "5× emit matrix sweep" while listing 6 tests
   (3 module + 3 program) → fixed to "6× emit matrix sweep (3 module
   + 3 program)" for explicit attribution
4. Cluster D banner "(~5)", actual sum = 2+3+2+2 = 9 → fixed to "(9)"
5. Line 7 (Purpose) stale singular `(test_pattern, dimension,
   required_paths_regex)` echo → fixed to `dimensions` plural;
   converges with openai-pro APPROVE_WITH_COMMENTS observation (review
   #9714) that had been deferred to follow-up — cursor's BLOCKING
   verdict overrides the deferral

§4 Open question 5 (pilot recommendation) also corrected from
"~6 tests" to "7 tests" for Cluster B consistency.

Clusters C/E/F/G/H/I banner counts re-verified against table sums
(7/12/6/10/7/5 respectively) — all already exact, no change needed.

P1 Modeling Faithfulness restored: every cluster banner now matches
its enumerated tests-column sum.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — fix skip_<cluster> polarity (openai-pro BLOCKING #9721 on PR #2721)

openai-pro re-review on PR #2721 at sha 93080af caught a critical
boolean polarity inversion in the skip_<cluster> formula. A Mgr/worker
following the brief literally would have wired the CI gate backward,
silently skipping affected tests — TESTING.md "test selection must
not skip affected behavior" violation + Boundary Discipline violation
(boolean carrier name and contract encoded opposite meanings).

**The bug**: 4 places stated post-dissolution `skip_<cluster>` formula
as `(affected_dimensions ∩ group.dimensions) ≠ ∅` (skip when
intersection NON-empty), while the CI consumer wires
`if: skip_<cluster> != 'true'` (run when skip is NOT true). Combined:
when intersection is non-empty (= affected), skip=true → tests don't
run → affected tests silently skipped.

**The fix**: invert the formula to `(intersection = ∅)` (skip when
intersection IS empty = no affected dim that this cluster reads). The
CI gate semantics stay the same; the polarity correction is on the
post-dissolution lens mapping.

Sites corrected:
- §1 hard-constraint para (line 9): replaced "(non-empty intersection
  means run)" with an explicit Boolean polarity block defining
  `skip = (intersection = ∅)` and equivalent `run = (intersection ≠ ∅)`
- §3 path-mapping intro (was line 132, now 142): same polarity fix
  + "Equivalently: `run = (intersection ≠ ∅)`"
- §4 open-question 4 (was line 186, now 196): "skip_<cluster> becomes
  `(intersection ≠ ∅)`" → `(intersection = ∅)` with explicit
  "same polarity: skip when no affected dim" note
- §5 acceptance (was line 206, now 216): same polarity fix +
  explicit "inverting the polarity silently skips affected tests" warning

All 4 references now consistent. Polarity table:
  intersection = ∅  → skip=true  → "do not run" (NOT affected, safe to skip)
  intersection ≠ ∅  → skip=false → "run" (affected, must run)

Director's brief #2719 likely has the same polarity issue and will need
parallel fix from the same authority chain. Flagging separately.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — cluster aggregation + path-regex verification discipline (codex BLOCKING on PR #2721)

codex BLOCKING review on PR #2721 at sha 262f42d caught two
substantive gaps:

**(1) Cluster aggregation predicate missing**: §3 defined per-row
intersection check but didn't specify how multi-row clusters
aggregate to the cluster-level `skip_<cluster>` boolean. A worker
following the brief could implement disjunction (any-row-empty
= skip cluster) which would silently skip the OTHER affected rows
in the cluster when only one row is unaffected.

Fix: explicit conjunction predicate in §3 + §4 + §5 + §6:
  skip_<cluster> = ∀ row ∈ cluster : (changed_files ∩ row.regex) = ∅
Equivalently: run_<cluster> = ∃ row ∈ cluster : row affected.

**(2) Path regexes PM-authored without source-tree verification**:
PM concrete `required_paths_regex` values in §3 were manually
authored from the inventory SHA references without validation
against actual paths in the source tree. Workers might wire CI
gates against stale paths.

Fix: explicit Mgr-verification discipline in §3 + §4 + §5 + §6:
- Workers MUST validate each concrete regex against source tree
  at HEAD before CI implementation
- Unverified or unverifiable regexes → `.*` per conservative
  fail-closed default
- Confidence column treated as audit priority (low → `.*` first,
  medium → audit then decide, high → audit but likely fine)
- Validation record kept (PR description or commit message)

Both fixes preserve the locked-design polarity from earlier
revisions:
- Per-row formula stays `(intersection = ∅)` for skip semantic
- Cluster aggregation is conjunction over rows (∀)
- Run formula is the structural complement (∃ ↔ ≠ ∅)

All 4 places updated: §3 path-mapping skeleton intro + §4 mechanism
+ §5 acceptance + §6 STOP triggers. Brief now structurally
guards against:
- polarity inversion (skip = ∅, not ≠ ∅; openai-pro caught prior)
- dimension cardinality narrowing (Set<Dimension>, not single; codex
  caught prior)
- cluster aggregation by disjunction (∀, not ∃; codex caught this)
- regex authoring without source-tree validation (codex caught this)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — fix stale dsl/std/ lens-paths (codex BLOCKING inline at line 152)

codex BLOCKING inline-review at line 152 (sha 262f42d) caught
that Cluster B's regex used stale `dsl/std/lens_cost.*\.dag` +
`dsl/std/cost.*\.dag` paths while the live cost-lens authority
is at `src/v3/lenses/cost.dag`. A change to the live authority
file would NOT match the stale regex → skip_b=true → cost-lens
tests silently skipped (P3 fail-closed + P2 single-authority
violation).

**Systematic audit + fix**: stale `dsl/std/<lens>.dag` pattern
applied across many rows (PM authored assuming lens .dag lived
in dsl/std/, but the live tree has them at src/v3/lenses/):

| Row | Old (stale)                                    | New (verified)                                                 |
|-----|------------------------------------------------|----------------------------------------------------------------|
| B   | dsl/std/lens_cost.*.dag + dsl/std/cost.*.dag   | src/v3/lenses/cost(_target_realization)?.dag                   |
| C-i | dsl/std/lens_idempotency.*.dag                 | src/v3/lenses/idempotency.dag                                  |
| C-p | dsl/std/lens_provenance.*.dag                  | src/v3/lenses/(provenance\|emission_provenance).dag            |
| C-u | dsl/std/lens_unused_parameters.*.dag           | src/v3/lenses/unused_parameters.dag                            |
| E×4 | dsl/std/(complexity\|cost\|symbolic_cost).*.dag | src/v3/lenses/(complexity\|cost).dag                           |
| F-b | dsl/std/boolean_algebra.*.dag                  | dsl/std/logic.dag (boolean-algebra concepts live there)        |
| G-c | dsl/std/complexity.*.dag                       | src/v3/lenses/complexity.dag                                   |
| G-l | dsl/std/(cost\|las\|crdt).*.dag                | `.*` (Mgr-fill; T-LAS substrate-deps not PM-traced yet)        |
| H-2 | dsl/std/parse.*.dag                            | src/v3/std/parse_surface.dag + src/v3/compiler/parse_tables.dag|
| H-2c| dsl/std/parse_tables.*.dag + dsl/std/tokenize  | src/v3/compiler/parse_tables.dag + src/v3/(compiler\|std)/tokenize.dag |
| H-w | dsl/std/workflow.*.dag                         | src/v3/std/workflows.dag                                       |

Confidence column dropped from `high` to `medium` for all
post-correction rows — Mgr should still validate each path
against live source tree at HEAD before CI implementation per
the verification-discipline added at d19a1a0. dissolution_note
column carries inline "**Path correction**: ..." annotations
documenting each fix for reviewer audit.

Cross-cluster bug-class catches now mapped on this template:
1. Dimension cardinality (Set<Dimension>; dedcf69)
2. Boolean polarity (skip = ∅; 262f42d)
3. Count discrepancies + line-7 singular (93080af)
4. Cluster aggregation predicate (∀ not ∃; d19a1a0)
5. Path-regex verification discipline (d19a1a0)
6. **Stale dsl/std/ lens-paths corrected to src/v3/lenses/** (this fix)

Brief structurally validated across 6 distinct axes.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — fix regex alternation escape (openai-pro APPROVE_WITH_COMMENTS on #2721)

openai-pro APPROVE_WITH_COMMENTS on PR #2721 at sha 45fc195 caught
a non-blocking regex error: line 185 had `src/v3/(compiler\|std)/tokenize.dag`
with `\|` (markdown-cell pipe escape), which a regex engine would
interpret as the literal string `compiler|std`, NOT as alternation
between `compiler` and `std`.

Mechanism of the bug:
- Markdown tables use `|` as column separator
- To put a literal `|` IN a cell (outside backticks), you escape with `\|`
- PM authored the regex with `\|` thinking the markdown-table escape
  was needed, but the regex is INSIDE backticks (code span) which
  preserves pipe character literally
- A worker copying the regex into ci.yml would silently miss
  tokenize.dag changes (only matches literal `compiler|std/tokenize.dag`)

Fix: drop the unnecessary `\` escape; markdown code spans preserve
`|` literally. Now regex correctly reads
`src/v3/(compiler|std)/tokenize.dag` — alternation between
src/v3/compiler/tokenize.dag and src/v3/std/tokenize.dag, both of
which exist per the source tree verified at 45fc195.

Mitigation: the template's own validation discipline at §3 + §5 §6
(workers MUST validate regex against live source tree before CI
implementation) would have caught this, but per openai-pro's read
"the concrete row should still not carry a known-bad example" — fair.

Cumulative bug-class catches on this template now 7 axes hardened:
1. Dimension cardinality (Set<Dimension>; dedcf69)
2. Boolean polarity inversion (skip = ∅; 262f42d)
3. Count discrepancies + line-7 singular (93080af)
4. Cluster aggregation predicate (∀ not ∃; d19a1a0)
5. Path-regex verification discipline (d19a1a0)
6. Stale dsl/std/ lens-paths corrected (45fc195)
7. Markdown-cell-escape leaking into regex semantics (this fix)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — Dimension enum is OPEN per design §2 + THESIS user-defined dims (codex BLOCKING on PR #2721)

codex BLOCKING inline-review at line 186-ish caught that my §6 STOP
trigger hard-rejected any `dimensions:` element outside the built-in
base set `{Value, Cost, Complexity, Effect, Refinement}` — which closes
the user-extensibility surface that THESIS + docs/design-affected-set-
lens.md §2 leave intentionally open with the trailing `...`.

Verification (codex was correct):

- `docs/design-affected-set-lens.md` §2: `⋃ over dim in {value, cost,
  complexity, effect, refinement, ...}` (note ellipsis = open enum)
- `THESIS.md` "User-defined dimensions" section: 'User-declared
  dimensions extend the same structural proof surface ... the ceiling
  of what gunbc can prove is user-extensible.'

The built-in base set ≠ the full enum. My template was treating them
as equivalent, which would have rejected valid user-defined dims at
the STOP gate (INVARIANTS P1 single-authority violation against
THESIS/design + P3 fail-closed violation since rejection-instead-of-
fail-closed is the opposite of safety).

Fixes:
- **§1** Dimension enum reference: rewrote with explicit `Dimension =
  {value, cost, complexity, effect, refinement, ...}` notation + the
  trailing `...` annotated as "OPEN for user-defined" + paragraph on
  THESIS user-extensibility framing + explicit instruction to treat
  unknown dim as fail-closed (always-run), NOT reject
- **§5** acceptance criterion: updated to reference the open enum +
  fail-closed-for-unknown behavior
- **§6** STOP trigger: now reads "cannot be carried as a typed
  Dimension at all (e.g., string-as-dimension, runtime-only)" — that's
  the genuine structural failure. Encountering a NEW user-defined
  dimension is NOT a STOP; it's a row carried as fail-closed-always-run

Cumulative bug-class catches on this template now 8 axes hardened
(was 7 before this fix; ci-skip-pattern-script wasn't applicable here):
1. Dimension cardinality (Set<Dimension>; dedcf69)
2. Boolean polarity inversion (skip = ∅; 262f42d)
3. Count discrepancies + line-7 singular (93080af)
4. Cluster aggregation predicate (∀ not ∃; d19a1a0)
5. Path-regex verification discipline (d19a1a0)
6. Stale dsl/std/ lens-paths corrected (45fc195)
7. Markdown-cell-escape leaking into regex semantics (7cbf29f)
8. **Dimension enum hard-closed rejecting user-defined** (this fix) —
   THESIS + design doc §2 explicitly leave open

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — carry user-defined Timing dim explicitly (codex BLOCKING on PR #2721)

codex BLOCKING re-review at sha c61a7ed line 197 (~193 in their
relay) caught a narrowing residual after the prior open-enum fix:
the `t_ci_workflow_as_data_demo_test` row carried `[Value, Cost]`
but the test actually evaluates `DimensionReport<TimingMeasurement>`
/ `ci_modeled_timing` — a user-defined Timing dim distinct from
generic Cost.

My prior open-enum fix (c61a7ed) updated §1/§5/§6 to ALLOW user-
defined dims but I didn't fix THIS row to USE one. Per the just-
established 'carry the dim, don't narrow' framing in §6, this row
should carry `[Value, Cost, Timing]` (or just `[Value, Timing]` if
Cost is sufficiently distinct from Timing in the test).

**Why it's load-bearing**: a future timing-only delta (e.g.,
DimensionReport schema change touching only timing fields, not Cost)
would be 'affected' for this test under the lens but the prior row
narrowed Timing → Cost → if Cost.affected = empty but Timing.affected
non-empty, test would be silently skipped (TESTING.md violation +
THESIS user-defined-dims framing violation).

Fix:
- Row dimensions: `[Value, Cost]` → `[Value, Cost, Timing]`
- Row dissolution-note: explicit annotation citing
  `DimensionReport<TimingMeasurement>` + `ci_modeled_timing` user-
  defined dim + the carrying-vs-narrowing rationale
- Self-references this template's own open-enum support per §1 —
  the row is now an in-table demonstration of the open-enum framing
  (consistency between framing and example)

This also re-stress-tests cluster aggregation: cluster H aggregates
over multiple rows including this Timing-carrying row, so cluster-
level skip computation correctly fail-closes when ANY row's dim
intersects with affected_dims.

Cumulative bug-class catches on this template now 9 axes hardened:
1. Dimension cardinality (Set<Dimension>)
2. Boolean polarity inversion (skip = ∅)
3. Count discrepancies + line-7 singular
4. Cluster aggregation predicate (∀ not ∃)
5. Path-regex verification discipline
6. Stale dsl/std/ lens-paths corrected
7. Markdown-cell-escape regex
8. Dimension enum hard-closed (open per THESIS)
9. **Narrowing user-defined dim to built-in** (this fix; carry don't normalize)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — codify 3-arm regex completeness invariant (mirror Director PR #2727 worker-brief discipline)

Director's PR #2727 absorbed Brian inline + codex BLOCKING convergent
finding on post-#2719 fail-open hole: per-group regex must include
THREE arms — deps + test-source + fixture — missing any is a
P3 fail-open boundary class.

This template (PR #2721) had the same structural issue: most PM-
authored rows have arms (1) deps + (2) test-source but lack arm (3)
`tests/dag/*.dag` fixture explicitly. Per Director's canonical
worker-brief discipline (PR #2727), this mirrors the gap and adds
the 3-arm completeness invariant to align.

Updates:
- §3 path-mapping intro: explicit 3-arm completeness invariant + per-
  arm fail-open semantics + audit note that PM-authored rows in §3
  below need Mgr fixture-arm audit for tests reading from
  `tests/dag/*.dag` (e.g., `t_pb_b_1_dag_runner_test` consumes
  `tests/dag/t_pb_b_1_*.dag`)
- §5 acceptance: new checklist item — every concrete regex includes
  arms (1) + (2) + (3) where applicable; Mgr-fill rejects missing
  arms 2/3
- §6 STOP triggers: two new STOP triggers for missing test-source
  arm OR missing fixture-arm-when-applicable
- Cross-link to Director PR #2727 / #2719 for canonical framing

This codifies but does NOT retrofit existing §3 rows — that's
Mgr-fill audit work (per the §3 disclaimer + Mgr-fill discipline).
PM signals the gap; Mgr fixes per row.

Cumulative bug-class catches on this template now 10 axes:
1. Dimension cardinality (Set<Dimension>)
2. Boolean polarity inversion
3. Count discrepancies + line-7 singular
4. Cluster aggregation predicate (∀ not ∃)
5. Path-regex verification discipline
6. Stale dsl/std/ lens-paths
7. Markdown-cell-escape regex
8. Dimension enum hard-closed (open per THESIS)
9. Narrowing user-defined dim (Timing→Cost)
10. **Missing test-source/fixture arms in regex** (this fix mirroring
    Director PR #2727 worker-brief discipline)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — restore `...` ellipsis in quoted §2 union formula (cursor APPROVE_WITH_COMMENTS-level exploratory on PR #2721)

cursor APPROVE review #9858 at sha 5c227c5 noted an exploratory
inconsistency: my quoted design-doc §2 union formula at lines 48-51
enumerated only the 5 built-in dimensions without the trailing `...`
that the actual `docs/design-affected-set-lens.md` §2 has, while my
surrounding text (lines 27-33, §1 enum reference) stresses the open-
enum framing.

Fix: restore the `...` in the quoted formula + add inline annotation
'← OPEN per §2; user-defined dims extend' so Mgr-fill readers can't
misread the box as closed.

Now lines 27-33 (open-enum framing) + lines 48-51 (formula quote) +
§5 acceptance + §6 STOP triggers all consistently affirm the open-
enum framing per THESIS user-defined dimensions.

Non-blocking exploratory observation; quick fix because the cost is
trivial (1-char + comment) and the value is internal-consistency
preservation.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — add test-source arm to 4 rows violating own 3-arm invariant (codex BLOCKING on PR #2721)

codex BLOCKING REQUEST_CHANGES at sha 8f11a35 caught my OWN 3-arm
completeness invariant being violated by 4 rows that ship concrete
regex but lack test-source arm. Per the invariant I codified in §3 +
§5 + §6, every concrete regex MUST include the OWN test-source arm
under `src/v3/compiler/tests/integration/`. These rows didn't:

1. `dimension::analyze_complexity_tests::.*` — had `tests/integration/dimension.*\.rs` arm but that file doesn't exist (tests live inline as a module in `tests/integration.rs`); arm matched nothing → fail-open
2. `dimension::fail_closed_tests::.*` — NO test-source arm
3. `e7_analyze_complexity_integration::.*` — NO test-source arm
4. `lane2_stage_2f_dimension_test::.*` — NO test-source arm
5. `sg2c1_parse_tables_authority_test::.*` — NO test-source arm

Fix: add test-source arm to each row:
- For inline modules (dimension/e7/lane2_stage_2f): test lives inline
  in `src/v3/compiler/tests/integration.rs`; add that path. Broad-but-
  correct per fail-closed default (any edit to integration.rs triggers
  these tests; a finer-grained match isn't expressible via path regex
  because the modules are inline in the file).
- For sg2c1 (standalone file): add explicit
  `src/v3/compiler/tests/integration/sg2c1_parse_tables_authority_test\.rs`.

Each row's dissolution_note now carries inline annotation citing the
codex BLOCKING finding + the test-source-arm correction rationale.

**Lesson**: codifying the invariant in §3/§5/§6 doesn't retrofit
existing rows — needed to AUDIT each concrete regex against the
invariant after codification. PM did partial audit on path correctness
(dsl/std → src/v3/lenses) but didn't re-audit for test-source-arm
presence. cursor #9858 noted earlier the boxed-formula inconsistency
in §1; codex now caught the same class on §3 row content. Audit
discipline = match-the-framing-everywhere, not just-codify-the-framing.

Cumulative bug-class catches on this template now 11 axes hardened:
1. Dimension cardinality (Set<Dimension>)
2. Boolean polarity inversion
3. Count discrepancies + line-7 singular
4. Cluster aggregation predicate (∀ not ∃)
5. Path-regex verification discipline
6. Stale dsl/std/ lens-paths
7. Markdown-cell-escape regex
8. Dimension enum hard-closed (open per THESIS)
9. Narrowing user-defined dim (Timing→Cost)
10. 3-arm regex completeness invariant codified
11. **Existing rows violated own 3-arm invariant** (this fix — codification didn't retrofit)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §1.8 row #105 — symbolic_cost_textbook_coverage_landed (Path A Tier 1 ratified per Director msg_ad5e934d) + §1.2/§1.5 interrogation probe refinement

Operator directive 2026-05-13 ("anything you would find in an algorithms textbook ... we need to land this all in R3 please") + Director ratification msg_ad5e934d (RATIFIED Path A + Tier 1 IN-R3 + Tier 2 R4-deferred + 5 sub-canvas questions routed to Substrate Mgr).

§1.8 row #105 changes:
- New gate symbolic_cost_textbook_coverage_landed; substrate-shape predicate-family; T-CostLens-Composition lane
- Tier 1 carrier extension: PROMOTE PolynomialCost { degree: DegreeAtLeastTwo } -> { degree: Rational } per dsl/std/rational.dag:26 Field<FieldOfFractions<Int>>; ADD PolyLogCost { exponent: Int } + ExponentialCost { base: Int } + FactorialCost; net 7 -> 11 variants per src/v3/std/algebra.dag:190-197
- Tier 2 R4-deferred: LogLogCost / InverseAckermannCost / IteratedLogCost / HyperExponentialCost (each requires consumer-evidence trigger)
- 5 sub-canvas questions for warm-wolf-698: (Q1) Rational dominance lattice ordering (Field<FieldOfFractions> lacks Order); (Q2) Linear-vs-Polynomial split reconciliation; (Q3) Sum/Product algebra interaction rules; (Q4) STOP-SIGNAL update; (Q5) canvas-shape authoring
- Two-part predicate: Part A (carrier landed via grep on type SymbolicCost) + Part B (algebra rules pass via cargo test)
- 5 Director-enumerated anti-patterns for post-ratification reviewers

§1.8 header gate-count updates (multiple lines):
- 104 enumerated -> 105 enumerated across plan, Q1 row, R3-close target arithmetic
- 103 R3-load-bearing -> 104 R3-load-bearing (only #11 canvas-deferred subtracted)
- Authority history extended: +Director ratification msg_ad5e934d + cost-textbook-coverage row #105 added 2026-05-13

§1.2 (Cost) interrogation probe refinement (post-PR-#2822 fix-forward):
- Promise updated to include #105 + R3-committed Tier 1 scope verbatim
- Split into Implementation probes (carrier scope) + Scope probes (Tier 1 textbook coverage with concrete bound examples: √n, exp, factorial, polylog, matrix mult) + Tier 2 boundary probes (R4-deferred bounds with expected behavior) + Falsification probes (Tier-3 recursive, Tier-2-not-named, STOP-SIGNAL trigger for Tier-1-coverable bound collapsing to UnknownCost)

§1.5 (User-defined dimensions) escape-hatch probes for Tier 2+:
- Compositional-mechanism probe per Director structural-extension caveat (if user-defined-dim supports cost-variant authoring with dominance lattice integration, Tier 2 R4-deferral is structurally bounded)
- Falsification probe: author a user-defined cost lens for inverse Ackermann; if it integrates -> R4-deferral bounded; if not -> load-bearing gap

Effort estimate: ~3-4 weeks total substrate work (carrier change + dominance lattice + Sum/Product algebra + testgen + parity validation); R3 close timeline extends accordingly.

Cascade: PM §1.8 row added (this PR) -> Substrate Mgr authors canvas (Q1-Q5) -> Director ratifies canvas -> worker dispatch -> gate #105 CONSUMER_LANDED -> PASSING through standard cycle.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §1.5/§1.7/§1/§3 — comprehensive 104→105 / 103→104 count sweep (operator BLOCKING on PR #2824:85 INVARIANTS P2)

Operator briansrls flagged at `docs/r3-program-plan.md:85` that PR #2824
introduced "105 enumerated" while the same §1.5 block still said "104
gate IDs" and "103 R3-load-bearing arithmetic", creating competing
authorities (INVARIANTS P2).

PR #2824's prior commit message claimed a header count sweep but the
diff only updated SOME of the count sites, leaving 10 lines internally
inconsistent. This commit completes the sweep.

Lines updated (all 104→105 / 103→104 where the count was a TOTAL or
LOAD-BEARING reference, not a row-number reference):

- §1.5 line 84: "104 gate IDs enumerated at this commit" → "105 gate IDs"
- §1.5 line 86: "103 R3-thesis = 104 − 1" → "104 R3-thesis = 105 − 1"
- §1.5 line 88: "forward-looking R3 close target is 103" → "104"
- §1.5 line 90: "Total: 87 + 16 + 1 = 104" → "Total: 87 + 16 + 2 = 105"
  (the +2 represents #104 + #105 routed to T-Lens-Behavioral-Parity +
  T-CostLens-Composition respectively; kept in trailing tail vs
  lane-incorporated to preserve the 2026-05-12 lane-breakdown snapshot's
  audit shape)
- §1.5 line 96: "103 R3-thesis = 104 − 1 = 103" → "104 = 105 − 1 = 104"
- §1 line 114: "103 R3-load-bearing gates green" → "104"
- §1.7 line 125: "DECLARE 104 closure gates" → "105"
- §1.8 line 338: "103 load-bearing" → "104"
- §2 line 627: "103 load-bearing" → "104"
- §Q-table line 805: "104 closure gates total" → "105"

Lines NOT updated (correct references to row numbers, not count totals):
- Lines 8, 84, 88, 90, 98, 108, 111, 148, 239 references to gates
  #98-#103 (T-WAD FULL R3) and gate #104 (Miss-class) and gate #105
  (cost-textbook) — these are row-number references, not totals
- §1.8 line 331/332 row entries (gate #103 ci_uses_affected_set,
  gate #104 lens_read_witness_shape_dissolved) — row identifiers

INVARIANTS P2 single-authority restored across §1.5 / §1.7 / §1 close
criteria / §2 close criteria / §Q-table.

Lesson: header-count sweep PRs MUST grep-verify every occurrence of
the prior counts before claiming the sweep is complete. PR #2824's
prior commit message overstated coverage; operator caught.

— sent from deep-wolf-155

* docs(r3-structure): add gate #104 + #105 to §Acceptance — restore single-authority parity with §1.8 (operator BLOCKING on PR #2824:207 INVARIANTS P2)

Operator briansrls flagged at `docs/r3-program-plan.md:207` that PR #2824
claims "the 105-gate ledger is consolidated with r3-structure.md" but
the diff doesn't update r3-structure.md, leaving #105 without the
canonical acceptance body that line 340 says lives there.

Audit found the gap is wider than #105 alone — gate #104
(`lens_read_witness_shape_dissolved`, added 2026-05-12 in a prior PR)
is also missing from r3-structure.md §Acceptance. Same INVARIANTS P2
single-authority violation class.

Fixed both in PR #2824 (cleanest bundle — same gap class, both rows
added to §Acceptance in their canonical lanes):

- **#105 `symbolic_cost_textbook_coverage_landed`** added to
  T-CostLens-Composition lane (after `cost_lens_reads_target_realization`
  + `coercion_cost_equals_complexity_by_construction`). Encodes Path A
  Tier 1 carrier extension shape (PolynomialCost{degree: Rational} +
  PolyLogCost + ExponentialCost + FactorialCost) + Tier 2 R4-deferral
  + structural-extension caveat + two-part predicate (Part A carrier
  landed + Part B algebra rules pass). Cross-refs §1.8 row #105 for
  full receipt + 5 sub-canvas substrate-shape questions.

- **#104 `lens_read_witness_shape_dissolved`** added to
  T-Lens-Behavioral-Parity lane (after `lens_capability_register_zero_
  proxy_zero_stub`). Encodes bundled-migration shape per Director
  ratification msg_915aa2c1 — (1) substrate-level Miss→Violates
  collapse across 70 sites in 6 files (cost.dag/complexity.dag/
  infer_helpers.dag/algebra.dag/substrate.dag/lookup.dag); (2)
  testgen-level universal-coverage TestClaim. Two-part predicate
  (Part A terminal + Part B regression guard). Cross-refs §1.8 row
  #104 for full receipt.

INVARIANTS P2 single-authority restored: §1.8 ledger ↔ §Acceptance
canonical body now in parity at gate-ID level for all 105 enumerated
gates (104 R3-load-bearing post-canvas-deferral).

Lesson logged: when adding §1.8 rows, r3-structure.md §Acceptance
must update in same PR. Prior PR #2824 commit message did not
include this discipline; #104's prior PR also missed it. Class
violation traceable to: section-anchor authoring discipline that
prevents the missing-mirror class.

— sent from deep-wolf-155

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant