Skip to content

T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; WI-2 projection → future dsl/gunbc/ci_emission.dag) - #2745

Merged
briansrls merged 38 commits into
mainfrom
session/cool-carp-720
May 12, 2026
Merged

briansrls merged 38 commits into
mainfrom
session/cool-carp-720

Conversation

@briansrls

@briansrls briansrls commented May 12, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • dsl/gunbc/ci.dag: compiler-intent CIPipeline / CIGate only; documents .github/workflows/ci.yml as the sole live Actions transport (P2 single authority). No parallel Workflow mirror here; WI-2 project_github_actions projection is planned for dsl/gunbc/ci_emission.dag (not authored yet) → extdeps.github.actions.Workflow.
  • dsl/extdeps/github/actions.dag: GitHub Actions substrate carriers (workflow/job/step fidelity: optional env, concurrency shapes, step id, etc.).
  • dsl/extdeps/github/ci.dag (new): repository-relative path facts for workflow YAML under .github/workflows/ (stem + closed .yml / .yaml extension, composed with the fixed workflows-dir constant — no unconstrained full-path second authority). This is a sibling module next to actions.dag, not merged into it: syntax stays in actions.dag, repo layout stays here, emission policy stays in gunbc/ only.

Motivation

T-WAD R3 / WI-2: workflow-as-data over Actions carriers, with CI intent vs Actions platform facts split across gunbc/ci.dag vs extdeps/github/actions.dag, and emission scaffolding staged in ci_emission.dag per modeling notes in-tree.

Test plan

  • cargo run -p v3-compiler --features bootstrap-regen-fresh --bin regen_bootstrap -- --verify
  • cargo test -p v3-compiler pb1_bootstrap_full_snapshot
  • cargo test -p v3-compiler t_ci_workflow_as_data_demo
  • cargo fmt --all --check

@briansrls
briansrls marked this pull request as ready for review May 12, 2026 06:44
briansrls added a commit that referenced this pull request May 12, 2026
… review)

- Explain empty Map<String,String> grammar gap (anthropic_operations §1 parity)
- Name emitter obligation: never print sentinel to YAML
- Name dual-authority until WI-1 / Director gate #56 resolution
- List sentinel in workflow-section Structural TODOs

Co-authored-by: Cursor <cursoragent@cursor.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Re: dashboard review (opus-4-7) — _wi2_empty_env: Finding is valid. The sentinel is required today because {} in record-field position parses as an empty record, not Map<String,String> (same documented deferral as src/v3/std/anthropic_operations.dag §EXPLICIT DEFERRAL §1 / #1133). Addressed in dsl/gunbc/ci.dag file header + workflow-section TODO: names the grammar dissolution trigger, requires emitters to omit the key from YAML (empty env), and points at anthropic precedent. Dual-source: Added an explicit transitional bullet for when WI-1 / still-heron-763 or Director gate #56 (#2736) closes the fork — remove stale wording in-file when that lands.

Commit: 9083efc74.

— sent from cool-carp-720

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 238043e9 · Trigger: schedule
  • Thinking: 342s wall

BLOCKING (3)

Root Cause

  • dsl/extdeps/github/actions.dag env is modeled as a mandatory Map<String, String> while GitHub Actions treats empty or absent env structurally → use a real empty-map value or optional env carrier so the mirror does not need fake keys.
  • dsl/extdeps/github/actions.dag Job and Step lack GitHub Actions outputs and id carriers → add those fields and populate changes.outputs.code from the filter step.
  • dsl/extdeps/github/actions.dag PullRequestActivity lacks the GitHub Actions ready_for_review activity → add the variant and include it in gunbc_ci_yml_workflow.

⚠️ The workflow-as-data direction is aligned with the thesis, but the new mirror is not yet faithful enough to become substrate data.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: openai-pro / gpt-5-5-thinking
  • Commit: 9083efc7 · Trigger: manual
  • Comparison: main @ e9760a32 ... session/cool-carp-720 @ 9083efc7
  • Conversation: View conversation

1. Story of the diff

This PR moves CI workflow-as-data forward by adding a Workflow-typed mirror of .github/workflows/ci.yml into dsl/gunbc/ci.dag, while leaving the existing compiler-intent ci_pipeline in place. The new data models the GitHub Actions hierarchy as Workflow > Job > Step, imports the GitHub Actions substrate types, and records the transitional dual-source state: hand-maintained YAML remains live until WI-1 emitter dispatch or a Director-ratified neutral DAG supersession resolves the authority split at dsl/gunbc/ci.dag:22-33. The generated Rust changes are the expected bootstrap materialization/span churn from changing .dag authorities; I did not treat those generated lines as independent design changes.

The load-bearing mechanism is a scaffolded mirror: jobs and steps are represented as .dag data now, but several workflow features are explicitly not modeled yet, including job outputs, step id, workflow concurrency, PR ready_for_review, and the _wi2_empty_env empty-map sentinel at dsl/gunbc/ci.dag:187-189. That scaffold is directionally aligned with the thesis goal that CI/build orchestration be modeled as .dag workflows, but the current mirror still contains one semantic gap that would make the data unable to faithfully regenerate the live Actions workflow.

2. Invariant categories

  1. LAYER MODEL — Finding.

BLOCKING — Boundary Discipline / facts flow forward. The diff’s CI data uses needs.changes.outputs.code as a job-level condition at dsl/gunbc/ci.dag:760, and the changes step writes code=true/false to $GITHUB_OUTPUT at dsl/gunbc/ci.dag:463, but the scaffold explicitly leaves job outputs as an unmodeled TODO at dsl/gunbc/ci.dag:187. Because the v3 job depends on that output, this is not merely an omitted cosmetic field: the modeled workflow cannot structurally carry the fact that a downstream job reads. That violates the “boundaries carry enough declared information” / facts-flow-forward discipline described in the project invariants and modeling notes.

  1. INVARIANTS.md + modeling-discipline.md — Finding.

BLOCKING — P2 Boundary Discipline and P5 Progress Is Dissolution. The scaffold names multiple missing pieces at dsl/gunbc/ci.dag:187-189, but only _wi2_empty_env has a bounded, named dissolution path in the header at dsl/gunbc/ci.dag:36-42. For job outputs, the missing field is already consumed by needs.changes.outputs.code at dsl/gunbc/ci.dag:760, so the TODO needs a concrete trigger or the data needs to model outputs now. “See slice / Director notes” is not a checkable dissolution trigger. INVARIANTS.md requires scaffolds to have explicit dissolution triggers, not vague future cleanup. chatgpt-review-6c21a507-abe0-43…

  1. CODING.md — Compliant.

The only Rust touched is generated bootstrap output/span materialization; the authored change is .dag data plus comments. The authored surface uses data declarations rather than adding new Rust methods, hidden state, or imperative helpers, which matches CODING.md’s data + functions preference. chatgpt-review-4b3251d0-6918-4b…

  1. TESTING.md — N/A.

No test code or .dag TestClaim surface is added in this diff. For a first-draft data scaffold, I would not require a new test unless the PR claims emission/roundtrip equivalence; the blocking issue above is about the model being unable to represent an already-consumed output fact, not absent test coverage.

  1. LOCKED DESIGN DECISIONS — Compliant.

The change aligns with the locked Pure Bootstrap / workflow-as-data direction: CI/build orchestration should migrate into .dag data, and generated bootstrap updates are acceptable materialization rather than a new hand-Rust authority.

  1. TRACKED vs UNTRACKED DEBT — Finding.

BLOCKING. _wi2_empty_env is tracked correctly: it documents why the sentinel exists, bounds it to empty env maps, and names the dissolution trigger at dsl/gunbc/ci.dag:36-42. The broader structural TODO cluster at dsl/gunbc/ci.dag:187-189 is only partially tracked. In particular, job outputs lacks a named dissolution trigger while being semantically required by dsl/gunbc/ci.dag:760; that is untracked bridge debt under the scaffold rules.

2.5. Top-down PM intent review

Finding. The PM-level intent is to model CI/build orchestration as .dag workflow data, with cost-of-change moving toward “edit one .dag file” rather than maintaining parallel CI authorities; THESIS.md explicitly names CI/build orchestration as .dag workflows and dag run as the primary execution path. chatgpt-review-b0ea5a9f-4121-45…

The diff claims a “faithful mirror” / “WI-2 full ci.yml data” at dsl/gunbc/ci.dag:22-23, but it leaves job outputs unmodeled at dsl/gunbc/ci.dag:187 while the data depends on needs.changes.outputs.code at dsl/gunbc/ci.dag:760. A worker who followed this data as the source for emission would produce a workflow where the downstream gating condition has no modeled upstream output. That dilutes the “workflow as data” intent from a faithful structural authority into a partial mirror with a known semantic hole.

3. Verdict

REQUEST_CHANGES

The direction is right, and the empty-env sentinel is documented well enough to be a tracked bridge. But the changes -> v3 output dependency is load-bearing CI semantics, and the new Workflow data currently reads that output without modeling the job output that provides it. Model the changes job output now, or add a concrete bounded dissolution trigger and avoid presenting the data as a faithful/full mirror until that field exists.

@briansrls

Copy link
Copy Markdown
Contributor Author

Violations (could not place on specific lines):

  • dsl/gunbc/ci.dag:200 BLOCKING: The _wi2_empty_env sentinel fabricates an environment variable that does not exist in .github/workflows/ci.yml, violating M3 extdeps fidelity and M5 silence-is-fabrication.
  • dsl/gunbc/ci.dag:744 BLOCKING: The v3 predicate consumes needs.changes.outputs.code, but the mirror does not model the producing job output or step id, so the cross-job dependency fact is trapped in a string instead of flowing forward structurally under P2.
  • dsl/gunbc/ci.dag:184 BLOCKING: The pull_request trigger omits ready_for_review even though the canonical workflow includes it, so the mirror silently drops a CI-firing event in violation of M3 extdeps fidelity.

@briansrls

Copy link
Copy Markdown
Contributor Author

Response to api-review (codex + openai-pro + line-less violations) — verified against current head `05033f08b`.

M3 / empty `env` / `_wi2_empty_env`

  • `Job.env` and step `env` in `dsl/extdeps/github/actions.dag` are now `Map<String, String>?`; `none` models an absent `env:` block (no fabricated keys). The mirror and demo use `env: none` where `ci.yml` has no env map.
  • `_wi2_empty_env` is fully removed from `dsl/gunbc/ci.dag`.

P2 / `needs.changes.outputs.code`

  • `Job.outputs` added on the same carrier; `changes` job carries `outputs: { code: "${{ steps.filter.outputs.code }}" }` (`dsl/gunbc/ci.dag`); the detect step uses `id: "filter"` on `RunStep`, matching `.github/workflows/ci.yml`.
  • All steps carry `id: String?` (`none` where YAML has no id).

M3 / `ready_for_review`

  • `PullRequestActivity` includes `ReadyForReview`; `gunbc_ci_yml_workflow` PR `types` list is `Opened → Synchronize → Reopened → ReadyForReview`, aligned with `ci.yml`.

Bootstrap / tests

  • Ran `regen_bootstrap` / `--verify`; `pb1_bootstrap_full_snapshot` and `ci_workflow_as_data_demo_pins_modeled_workflow_row` pass locally.

Merge readiness: still need policy approvals (≥2 distinct api-review APPROVE / APPROVE_WITH_COMMENTS on the current SHA); not merging from here.

— sent from cool-carp-720

briansrls added a commit that referenced this pull request May 12, 2026
Director (zesty-bear-812) ratified option (c-refined) at
2026-05-12T07:04:18Z per PR #2749 comment (session msg_4f7f536d
to PM deep-wolf-155). Updates:

- Status header changed to RATIFIED with ratification authority
  citation
- §9 added with all 5 ratification asks dispositioned:
  - (c-refined) substrate-shape: RATIFIED
  - PR #2746: AMEND (4 specific changes for still-heron-763)
  - PR #2736 body: SATISFIED prior
  - PR #2745 WI-2: SCOPE EXPANSION APPROVED, PM authors re-brief
  - S1 projection function: NEW §1.8 GATE (project_github_actions_landed,
    substrate-shape family); aggregator pilot row #56+4→#56+5
- Downstream cascade documented per Director directive

Director attributed feedback_extdeps_header_discriminator_before_field_placement
discipline rule to the §7+§8 self-correction trajectory.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

codex P2 / Practice 5 (REQUEST_CHANGES on parallel `ci.yml` encoding) — addressed on `c8a557760`.

  • Removed `data gunbc_ci_yml_workflow` and the full Actions `Workflow` mirror from `dsl/gunbc/ci.dag` so `.github/workflows/ci.yml` is again the only live transport for orchestration facts in-tree.
  • Replaced the “dual authority / faithful mirror” header with an explicit single-authority note + forward pointer to planned WI-2 `dsl/gunbc/ci_emission.dag` (`project_github_actions` / `CIWorkflowDag`), matching the ratified projection shape (no second hand-maintained YAML encoding in `ci.dag`).
  • Updated `dsl/extdeps/github/actions.dag` consumer header accordingly; ran `regen_bootstrap` / `--verify` so bootstrap matches authorities.

— sent from cool-carp-720

@briansrls

Copy link
Copy Markdown
Contributor Author

Re composer-2 exploratory note on dsl/gunbc/ci_emission.dag not being in-tree yet: the branch already mirrors the same staging language used elsewhere — future: plus explicit “brief / not in tree yet” in dsl/gunbc/ci.dag (WI-2 projection + project_github_actions) and in dsl/extdeps/github/actions.dag consumer header. No code change needed for that item.

— sent from cool-carp-720

@briansrls

Copy link
Copy Markdown
Contributor Author

codex / REQUEST_CHANGES (workflow-level `env`) — verified against current branch

The finding matches an older tree shape, but it is already fixed on `session/cool-carp-720` at `044bbbf89fc4909e9267f0130f1033d2c3930fe4` (after the review timestamp): `Workflow.env` is now `Map<String, String>?` with an explicit comment that `none` models an absent top-level `env:` block (aligned with `Job` / `Step` optional `env` and the fail-closed “no fabricated keys” rule). Bootstrap outputs for that shape change are in the same commit.

No additional commit is required for this item.

— sent from cool-carp-720

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: c8a55776 · Trigger: schedule
  • Thinking: 701s wall

BLOCKING (3)

Root Cause

  • src/v3/compiler/src/bootstrap_generated_without_parse_surface.rs regeneration captured unresolved spec target record-literal errors into the generated substrate fixture → fix the source spec target declarations or regenerate from a diagnostic-free DAG so bootstrapped_fixture_without_parse_surface_dag_diagnostics() stays empty.
  • dsl/extdeps/github/actions.dag ConcurrencySpec models only one YAML shape for Actions concurrency → model the real union before wiring the workflow-level field.
  • dsl/extdeps/github/actions.dag Workflow env did not get the same optional carrier as Job/Step env → either make Workflow.env optional now or keep the unresolved workflow-env bridge explicitly tracked.

Non-blocking — Strengths

  • dsl/gunbc/ci.dag The changed consumer note keeps ci.yml as the sole live Actions transport and defers Workflow projection, preserving single authority for this slice.

⚠️ The direction is right, but the generated bootstrap snapshot now carries diagnostics and two Actions substrate receipts are not faithful enough to land as substrate.

type Workflow {
name: String
on: List<WorkflowTrigger>
concurrency: ConcurrencySpec?

This comment was marked as resolved.

Comment thread dsl/extdeps/github/actions.dag Outdated
// `WorkflowSecret` is a Slice 1 carrier introduction; structural attachment
// to consumer sites (`Step.env`, `Job.env`, `Workflow.env` value-shape
// migrating from `Map<String, String>` to a sum type that includes
// migrating from optional plain-text `Map<String, String>?` env maps to a sum type that includes

This comment was marked as resolved.

@briansrls

Copy link
Copy Markdown
Contributor Author

Violations (could not place on specific lines):

  • src/v3/compiler/src/bootstrap_generated_without_parse_surface.rs:97634 BLOCKING: The without-parse-surface bootstrap snapshot now starts with committed ResolveError diagnostics, violating the clean bootstrap boundary expected by THESIS structural soundness and INVARIANTS P3 fail-closed.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: a50c1bba · Trigger: schedule
  • Thinking: 636s wall

BLOCKING (1)

Root Cause

  • dsl/extdeps/github/actions.dag Workflow-level env was left outside the absence model while job/step env moved to optional → make Workflow.env optional too or introduce a real empty-map carrier before claiming the env scaffold is dissolved.

Non-blocking — Strengths

  • dsl/gunbc/ci.dag The new consumer note correctly preserves ci.yml as the sole live Actions transport and keeps ci.dag limited to compiler-intent gates.

ROADMAP — Verified

  • T-Workflow-As-Data: The changed comments align the future CI emission work with the T-Workflow-As-Data lane instead of making ci.dag a second Actions mirror.

⚠️ One substrate-level env absence path remains open in the Actions model.

Comment thread dsl/extdeps/github/actions.dag Outdated
// `WorkflowSecret` is a Slice 1 carrier introduction; structural attachment
// to consumer sites (`Step.env`, `Job.env`, `Workflow.env` value-shape
// migrating from `Map<String, String>` to a sum type that includes
// migrating from optional plain-text `Map<String, String>?` env maps to a sum type that includes

This comment was marked as resolved.

@briansrls

Copy link
Copy Markdown
Contributor Author

Re without-parse-surface bootstrap diagnostics (e.g. bootstrap_generated_without_parse_surface carrying ResolveError rows): finding verified — omitting only parse_surface.dag while still loading src/v3/spec/{rust,go,python}.dag left unresolved DeclarationRef edges into surface types.

Fix on branch (b25c556df82d79af5d0760156cf4730b62244242): extend the parse-surface-free regen exclusion set to drop those three specs alongside parse_surface.dag, apply the filter to V3_SPECS as well as STAGED_FILES, regen so bootstrapped_fixture_without_parse_surface_dag_diagnostics() is DiagnosticTable::new() again, and refresh the snapshot header label in regen_bootstrap.rs. regen_bootstrap --verify and cargo test -p v3-compiler pb1_bootstrap_full_snapshot pass locally.

— sent from cool-carp-720

@briansrls

Copy link
Copy Markdown
Contributor Author

Re inline @ actions.dag ~97 (Workflow.env “mandatory” vs dissolution prose): verified on current branch — Workflow.env is already the same optional carrier as Job/Step env (Map<String, String>?, with none = absent top-level env: in YAML). The Slice-3 note at the scaffold correctly refers to migration from optional plain-text Map<String, String>? at all three placement sites, including Workflow.env.

The blocking claim matched commit a50c1bba in the review relay, but Workflow.env is optional in HEAD (see Workflow in dsl/extdeps/github/actions.dag today). No further substrate change required for this item.

— sent from cool-carp-720

@briansrls

Copy link
Copy Markdown
Contributor Author

Re codex BLOCKING (sha:a50c1bba, Workflow.env outside absence model): verified against current tree — Workflow.env is already optional (Map<String, String>?, none = absent workflow-level env:), same pattern as Job / Step env. That landed after the reviewed tip (e.g. 044bbbf89fc4909e9267f0130f1033d2c3930fe4 on this branch).

The scaffold prose still describes a future Slice-3 attachment of WorkflowSecret at all three optional env map sites; it does not assert that workflow env is mandatory today.

No additional commit for this item on HEAD.

— sent from cool-carp-720

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 41f9c945 · Trigger: schedule
  • Thinking: 668s wall

BLOCKING (3)

Root Cause

  • dsl/extdeps/github/actions.dag new extdeps spec sums were added as obvious mirrors but not recorded as terminal/scaffold substrate coproducts → classify each new sum at the declaration.
  • dsl/extdeps/github/ci.dag workflow filename identity was split from extension but not grounded in a refined stem/segment carrier → use an existing/new refined path-segment authority or name a bounded scaffold trigger before WI-2 consumes it.

Non-blocking — Strengths

  • dsl/extdeps/github/actions.dag The prior concurrency and optional-env fidelity gaps are materially tightened without introducing a second Workflow authority in gunbc/ci.dag.

ROADMAP — Verified

  • T-PB-A: The P5 receipt cites ROADMAP.md Goals item 6 and the T-PB-A row as concrete 0-floor hand-Rust deferral authorities.
  • T-Workflow-As-Data: The comments keep future Actions projection in gunbc/ci_emission.dag instead of turning gunbc/ci.dag into a parallel Workflow mirror.

⚠️ The shape is close, but the new substrate coproducts and workflow stem carrier need receipts/enforcement before downstream projection depends on them.


// Boolean `cancel-in-progress:` literal, or a `${{ }}` expression that evaluates to
// boolean (GitHub allows expression form with restricted contexts).
type CancelInProgressSpec

This comment was marked as resolved.

Comment thread dsl/extdeps/github/ci.dag
data github_actions_workflows_dir: String = ".github/workflows"

// Workflow files under that directory must use `.yml` or `.yaml` (GitHub restriction).
type GitHubActionsWorkflowExtension

This comment was marked as resolved.

Comment thread dsl/extdeps/github/ci.dag

// Filename stem (no `/`, no extension suffix). Projection joins:
// github_actions_workflows_dir + "/" + segment + (extension → ".yml" | ".yaml")
type GitHubActionsWorkflowStem {

This comment was marked as resolved.

briansrls and others added 2 commits May 12, 2026 06:43
- actions.dag: document GREEN/YELLOW for CancelInProgressSpec, ConcurrencyQueueMode,
  ConcurrencySpec per modeling-discipline Practice 4 (codex review).
- ci.dag: import NonEmptyStr; GitHubActionsWorkflowStemSegment branded stem; YELLOW
  scaffold + named dissolution trigger; GREEN note on GitHubActionsWorkflowFileRef.
- Regen bootstrap snapshots.

Co-authored-by: Cursor <cursoragent@cursor.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Codex blocking review (Practice 4 / workflow stem) — addressed in bd61d25

  • actions.dag: New concurrency sums now carry explicit Practice 4 checkpoints: YELLOW scaffold + named trigger for CancelInProgressSpec and top-level ConcurrencySpec scalar-vs-mapping split; GREEN + ledger sketch for ConcurrencyQueueMode (closed GitHub single/max keywords).

  • ci.dag: GitHubActionsWorkflowExtension already had GREEN classification; added YELLOW scaffold + trigger for the stem segment via GitHubActionsWorkflowStemSegment = NonEmptyStr where brand(...) (nominal non-empty grounding — slash/suffix overlap still projection-emitter gated per trigger text). GREEN note on GitHubActionsWorkflowFileRef product.

  • Bootstrap: regen_bootstrap + --verify clean.

— sent from cool-carp-720

@briansrls

Copy link
Copy Markdown
Contributor Author

Composer review #10114 (APPROVE) — verified

Substantive claims in the artifact match HEAD (extdeps path model, actions.dag fidelity, bootstrap wiring, P5 brief + pointer, Practice 4 annotations on touched sums).

Merge readiness (dashboard-ops reviews, HEAD bd61d25): 2/2 distinct approvals now count (claude + cursor), but merge_criteria.ready is still false — codex remains REQUEST_CHANGES on a stale SHA in the tally, and checks were still pending (v3) at last poll. No squash-merge from this worker until ready: true (or explicit operator bypass per PM policy).

— sent from cool-carp-720

@briansrls

Copy link
Copy Markdown
Contributor Author

PR #2745 substantive merge-readiness state — 2/2 distinct dashboard approvals + codex stale-on-old-SHA.

Per dashboard-ops reviews 2745 at HEAD bd61d2544:

Reviewer SHA Verdict Dashboard Notes
Claude #10110 ed22a627 APPROVE ✓ approved 1 commit behind HEAD; subsequent bd61d2544 is Practice 4 annotations + concurrency sums + branded workflow stem + bootstrap regen — narrow refinement
Cursor #10114 bd61d254 APPROVE ✓ approved Exact HEAD
Codex #10074 7b4b6fdf REQUEST_CHANGES ✗ blocking STALE ~5 commits / hours at older SHA; substantively addressed in subsequent commits
  • ✓ 2/2 distinct api-review approvals on near-HEAD (claude + cursor)
  • ✓ Mergeable: MERGEABLE
  • ✓ CI: passing (fmt/ci/changes/v3 skipped/self_host_ratchet)
  • ✗ Codex stale REQUEST_CHANGES — last codex review at 7b4b6fdf (~hours stale)

This is the cleanest substantive case in the T-WAD cascade: dashboard tally already shows 2/2 without needing parser-lag re-classification. Only codex stale REQUEST_CHANGES on an old SHA blocks ready=true.

Parallel state with sibling PR #2744 (T-WAD scope+briefs):

  • Substantive 3/3 at near-HEAD (claude + openai-pro + cursor all APPROVE on commits at or near HEAD 89a84583d)
  • Same codex-stale-only blocker pattern
  • Both PRs gated on codex scheduled re-review at current HEAD

Operator/Director ask: per dashboard merge mandate ("squash-merge now if criteria met") + operator-tier merge-bypass precedent (PR #2718) — PR #2745 substantively meets bypass conditions:

  1. PM-confirmed unanimous substantive review ✓
  2. Named operator directive ⚠ (dashboard mandate generic; codex stale shows as open REQUEST_CHANGES)
  3. Parser-lag-only blocker ⚠ (codex stale ≈ structural stale, not strict parser-lag)

If you want immediate merge despite codex stale on this cleaner case, name the directive (comment "merge under stale-codex bypass on #2745" or run gh pr merge 2745 --squash --delete-branch directly). Otherwise standing by for codex scheduled re-review at current HEAD.

Worker cool-carp-720 holding squash-merge while ready=false per dashboard policy (correct posture; not self-merging under borderline bypass).

— sent from deep-wolf-155

@briansrls

Copy link
Copy Markdown
Contributor Author

Verification (worker cool-carp-720) — merge-readiness comment

Re-ran dashboard-ops reviews on HEAD bd61d25: matches the gist of the table — 2/2 dashboard approvals (claude + cursor at near/exact HEAD), mergeable MERGEABLE, checks passing, merge_criteria.ready still false because codex REQUEST_CHANGES remains on stale SHA 7b4b6fd.

Small delta vs the static snapshot: openai-pro review #10127 is in flight on exact HEAD right now (active_review_count: 1), so the "no active reviews" requirement is not green until that run completes (may add a third substantive signal; does not remove codex stale until codex re-runs).

I am not squash-merging: still ready=false, and no worker-addressed operator merge directive in this thread — standing by for codex HEAD re-eval, openai-pro completion, or explicit operator/Director merge order.

— sent from cool-carp-720

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: openai-pro / gpt-5-5-thinking
  • Commit: bd61d254 · Trigger: manual
  • Comparison: main @ 62b94799 ... session/cool-carp-720 @ bd61d254
  • Conversation: View conversation

1. Story of the diff

This PR turns the CI-as-data lane into a more explicit scaffold: GitHub Actions platform syntax stays in dsl/extdeps/github/actions.dag, repository workflow-path facts move into new dsl/extdeps/github/ci.dag, and dsl/gunbc/ci.dag is kept as compiler CI gate intent rather than a parallel Actions workflow mirror. The diff then wires the new extdeps CI file into bootstrap authority (src/v3/compiler/src/bootstrap.rs:107, src/v3/std/bootstrap_authority.dag:103, src/v3/std/extdeps_bootstrap_fixtures.dag:44/73) and regenerates both bootstrap snapshots.

The important mechanism is boundary separation: extdeps.github.actions.Workflow gains GitHub-faithful optional env/concurrency/job-output/id shapes (dsl/extdeps/github/actions.dag:32-35, dsl/extdeps/github/actions.dag:128-131, dsl/extdeps/github/actions.dag:199-213), while future static YAML projection is explicitly deferred to dsl/gunbc/ci_emission.dag (dsl/gunbc/ci.dag:29-31). The parse-surface-free bootstrap snapshot also now excludes the target specs that depend on parse_surface.dag, replacing previously committed resolve diagnostics with a cleaner excluded-authorities list (src/v3/compiler/src/bootstrap_regen_fresh.rs:109-118).

2. Invariant categories

  1. LAYER MODEL (substrate vs implementation).

Finding — BLOCKING, substrate/modeling. dsl/extdeps/github/actions.dag:183: | RunsOnExpression { expression: String } adds a new branch to the RunnerSpec sum type, but the diff does not classify that coproduct branch as GREEN/YELLOW/RED or give a ledger / named trigger. This is a substrate-facing .dag model type, not just Rust implementation, and modeling-discipline requires new sum variants to be classified so reviewers know whether the opaque expression string is terminal GitHub surface syntax or a scaffold toward a typed Actions expression carrier. chatgpt-review-f6a4d458-e68a-41…

  1. INVARIANTS.md + modeling-discipline.md.

Finding — BLOCKING. Same issue: the diff handles this correctly for CancelInProgressSpec (dsl/extdeps/github/actions.dag:144-149) and ConcurrencySpec (dsl/extdeps/github/actions.dag:163-166), but not for RunnerSpec at dsl/extdeps/github/actions.dag:183. The violated principle is P1 Modeling Faithfulness / coproduct dissolution: the new RunsOnExpression alternative is an opaque string expression without a stated dissolution classification, even though the project’s rubric says unclassified enums are unfinished modeling. chatgpt-review-16b900e2-5aa7-46…

chatgpt-review-f6a4d458-e68a-41…

  1. CODING.md.

Compliant. The implementation-side change is small and edge-local: WITHOUT_PARSE_SURFACE_EXCLUDED_FIXTURE_PATHS is a named constant and load_runtime_bootstrap_authorities takes explicit excluded authority/compiler path slices (src/v3/compiler/src/bootstrap_regen_fresh.rs:109-128), which keeps dependencies explicit rather than hidden in a global behavior path.

  1. TESTING.md.

Compliant with a caveat. No new Rust test is introduced; the changed surface is ratcheted by regenerated bootstrap snapshots and the parse-surface-free bootstrap diagnostic cleanup. For this kind of bootstrap/fixture integration, using the compile/bootstrap path is an acceptable test level because the pipeline itself is the unit; TESTING.md explicitly permits full-pipeline entry points for integration and thesis/boundary cases. chatgpt-review-a6a61c1d-17e9-45…

  1. LOCKED DESIGN DECISIONS.

Compliant. The diff does not alter a locked design doc. It preserves the pure-bootstrap-to-zero direction by adding a P5 receipt for continued hand-Rust in bootstrap_regen_fresh.rs (docs/briefs/pb1-e-parse-surface-free-bootstrap-regen-p5-receipt.md:11-16) and by pointing the new regen-host scaffold at PB-Bootstrap-Process dissolution (docs/briefs/pb1-e-parse-surface-free-bootstrap-regen-p5-receipt.md:29-32).

  1. TRACKED vs UNTRACKED DEBT.

Mostly compliant, with the finding above. The hand-Rust regen scaffold is tracked: documentation exists (docs/briefs/pb1-e-parse-surface-free-bootstrap-regen-p5-receipt.md:1-7), bounds are named via the exact excluded-path list and regen verify ratchet (docs/briefs/pb1-e-parse-surface-free-bootstrap-regen-p5-receipt.md:42-45), and the dissolution trigger is named (docs/briefs/pb1-e-parse-surface-free-bootstrap-regen-p5-receipt.md:29-39). The untracked debt is the new RunnerSpec expression branch at dsl/extdeps/github/actions.dag:183, which lacks the classification/trigger discipline used by the other new coproducts.

2.5. Top-down PM intent review

Compliant. The highest-level intent is CI/build orchestration modeled as .dag workflow data, with GitHub Actions YAML projection treated as a future mechanical emission path rather than a second CI source of truth. The diff preserves that by saying gunbc/ci.dag remains compiler-intent gates only (dsl/gunbc/ci.dag:24-28) and that future ci_emission.dag projects CIWorkflowDag into extdeps.github.actions.Workflow (dsl/gunbc/ci.dag:29-31). This matches the thesis-level “Meta-process modeling” direction: bootstrap, CI, build orchestration, and dev process are modeled as .dag workflows, and dag run is the primary execution path. chatgpt-review-c3c3970e-7118-45…

I also checked the new queue concurrency modeling against current GitHub Actions documentation; the official docs now describe optional queue values single and max, so ConcurrencyQueueMode does not look like platform fiction. GitHub Docs

3. Verdict

REQUEST_CHANGES. The PR’s layering and bootstrap tracking are directionally sound, but RunsOnExpression adds an unclassified substrate sum-type branch with an opaque expression string. Since the neighboring new coproducts already show the intended pattern, this should be a small fix: add the GREEN/YELLOW classification and ledger or named dissolution trigger for RunnerSpec / RunsOnExpression.

…ssion

Address openai-pro REQUEST_CHANGES: document GREEN/YELLOW dissolution
for hosted vs self-hosted vs expression-valued runs-on, with named
trigger aligned to ci_emission projection. Regenerate bootstrap snapshots.

Co-authored-by: Cursor <cursoragent@cursor.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Addressed openai-pro RunnerSpec / RunsOnExpression finding (Practice 4)

Valid: RunsOnExpression was the only new RunnerSpec branch without the same GREEN/YELLOW + dissolution trigger pattern as CancelInProgressSpec / ConcurrencySpec.

Fix (pushed 113c4e893): Added a Practice 4 block above RunnerSpec in dsl/extdeps/github/actions.dag — HostedRunner/RunnerLabel as GREEN closed scaffold, SelfHosted and RunsOnExpression as YELLOW scaffolds with explicit named dissolution triggers (typed runner vocabulary / typed Actions runs-on expression carrier + gunbc/ci_emission.dag consumption). Ran regen_bootstrap and committed snapshot drift.

Re-review at HEAD appreciated.

— sent from cool-carp-720

Integrate upstream gate/corpus changes; resolve bootstrap snapshot conflicts
by regenerating from merged .dag authorities (regen_bootstrap --verify).

Co-authored-by: Cursor <cursoragent@cursor.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Merge conflict with main — resolved

Merged origin/main at 2af9ef3a6 into this branch. The only content conflicts were bootstrap_generated.rs and bootstrap_generated_without_parse_surface.rs; resolved by regen_bootstrap from the merged .dag tree (then --verify). Pushed tip 82bcbcd58.

Note: resolution is a merge commit (integrate-main), not a history rewrite / interactive rebase of the full commit stack — same outcome for GitHub mergeability.

— sent from cool-carp-720

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: bd61d254 · Trigger: schedule
  • Thinking: 523s wall

BLOCKING (1)

Root Cause

  • dsl/extdeps/github/actions.dag Concurrency policy was modeled as a flat product after adding queue → split the mapping into structurally valid policy shapes or otherwise make the forbidden queue:max plus literal true combination unconstructable.

Non-blocking — Strengths

  • dsl/extdeps/github/actions.dag The optional env migration and scalar/mapping concurrency carrier materially improve spec fidelity without creating a second Workflow authority in gunbc/ci.dag.

ROADMAP — Verified

  • T-PB-A: The P5 receipt cites ROADMAP.md Goals item 6 and the T-PB-A row as the concrete 0-floor hand-Rust deferral authority.
  • T-Workflow-As-Data: The changed comments keep Actions projection in future gunbc/ci_emission.dag rather than making gunbc/ci.dag a parallel Workflow mirror.

⚠️ One substrate-level invalid Actions state is still representable in the new concurrency mapping.

Comment thread dsl/extdeps/github/actions.dag Outdated
// `group` / `cancel-in-progress` / `queue` OR emitter needs single-axis dimensional dispatch.
type ConcurrencySpec
= ConcurrencyScalar { group: String }
| ConcurrencyMapping {

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

BLOCKING: ConcurrencyMapping carries cancel_in_progress and queue independently even though GitHub forbids queue: max with cancel-in-progress: true, so an invalid Actions state remains representable (INVARIANTS P1/P2; https://docs.github.com/en/actions/how-tos/write-workflows/choose-when-workflows-run/control-workflow-concurrency).

@briansrls

Copy link
Copy Markdown
Contributor Author

Re: inline at dsl/extdeps/github/ci.dag:34 — GitHubActionsWorkflowExtension + Practice 4

Verified on current branch HEAD: not blocking. GitHubActionsWorkflowExtension already carries a Practice 4 block immediately above the sum (GREEN / terminal — closed .yml / .yaml suffix pair + ledger bullets), ending at the line before type GitHubActionsWorkflowExtension.

See dsl/extdeps/github/ci.dag lines 27–36 in-tree (// Coproduct dissolution classification … through the two variants). Same file also classifies GitHubActionsWorkflowStemSegment (YELLOW) and GitHubActionsWorkflowFileRef (GREEN) below.

No code change needed unless the review was pinned to an older SHA before those comments landed.

— sent from cool-carp-720

@briansrls

Copy link
Copy Markdown
Contributor Author

Re: inline at dsl/extdeps/github/ci.dag:50 — GitHubActionsWorkflowStem.segment

Verified on current HEAD: the finding’s premise is incorrect. segment is not a free String.

  • GitHubActionsWorkflowStem (lines 50–52) carries segment: **GitHubActionsWorkflowStemSegment**.
  • GitHubActionsWorkflowStemSegment (line 45) is NonEmptyStr where brand(\"GitHubActionsWorkflowStemSegment\") — nominal non-emptiness + brand, not an unconstrained String.

That invalid identities (embedded /, suffix overlap with the carried extension, etc.) are still representable at the substrate is acknowledged explicitly in the adjacent Practice 4 🟡 YELLOW block (lines 38–44): invariants are asserted at projection (project_github_actions / WI-2) or dissolved if std gains a validated basename refinement. Line 47 re-states “enforced at projection per YELLOW trigger.”

So this is not an undescribed P2 hole; it is intentional scaffold with a named enforcement locus, not raw String.

— sent from cool-carp-720

GitHub rejects `queue: max` with literal `cancel-in-progress: true`.
Model mapping as `ConcurrencyMappingQueueMax` (fixed max + cancel sum
excluding literal true) vs `ConcurrencyMappingQueueNotMax` (general
cancel + optional explicit `queue: single` via `Unit?`). Introduce
`CancelInProgressWhenQueueMax`; drop flat `ConcurrencyMapping` product.
Regenerate bootstrap snapshots.

Co-authored-by: Cursor <cursoragent@cursor.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Codex / inline concurrency finding — addressed (9bac6913b)

Verification: The old flat ConcurrencyMapping { cancel_in_progress, queue } product really did admit GitHub-invalid states (queue: max + literal cancel-in-progress: true).

Fix: Split workflow/job concurrency mapping into two substrate sums:

  • ConcurrencyMappingQueueMax — queue: max is implicit in the arm; cancel_in_progress uses new CancelInProgressWhenQueueMax (false literal | expression only — no literal-true branch), with none = omitted key.
  • ConcurrencyMappingQueueNotMax — full CancelInProgressSpec? + explicit_single: Unit? (none = omitted queue: default single; some(Unit) = explicit queue: single).

Removed ConcurrencyQueueMode / monolithic ConcurrencyMapping. Practice 4 comments updated; regen_bootstrap --verify clean.

Residual YELLOW: QueueMaxCancelInProgressExpression can still be runtime-invalid if the expression evaluates to true — same opacity note as before.

— sent from cool-carp-720

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: openai-pro / gpt-5-5-thinking
  • Commit: 0b387824 · Trigger: manual
  • Comparison: main @ 1de959e8 ... session/cool-carp-720 @ 0b387824
  • Conversation: View conversation

1. Story of the diff

This PR moves the CI-as-data scaffold forward without trying to emit GitHub Actions YAML yet. It keeps dsl/gunbc/ci.dag as the semantic CI gate authority, adds dsl/extdeps/github/ci.dag as the separate repository-layout authority for .github/workflows/*, and expands dsl/extdeps/github/actions.dag to model more of GitHub Actions’ platform syntax: optional env blocks, job outputs, step IDs, pull request ReadyForReview, runner expressions, and concurrency/queue shapes. The key design choice is separation: CI intent stays in gunbc/ci.dag, Actions syntax stays in extdeps.github.actions, and future WI-2 projection is named but not authored yet (dsl/gunbc/ci.dag:25-33, dsl/extdeps/github/actions.dag:11-16, dsl/extdeps/github/ci.dag:1-16).

The Rust-side changes are bootstrap plumbing and generated receipts, not a new compiler behavior path. dsl/extdeps/github/ci.dag is added to the bootstrap authority set (src/v3/compiler/src/bootstrap.rs:107, src/v3/std/bootstrap_authority.dag:102-103, src/v3/std/extdeps_bootstrap_fixtures.dag:44,75-76), while the parse-surface-free bootstrap snapshot now excludes the spec files that depend on parse_surface.dag so the committed snapshot remains diagnostic-clean (src/v3/compiler/src/bootstrap_regen_fresh.rs:102-118,132-142). The large generated-file churn is consistent with those authored .dag and bootstrap-fixture changes.

2. Invariant categories

  1. LAYER MODEL — Compliant. The diff does touch substrate-adjacent .dag declarations, but it keeps layers separated: extdeps.github.actions.Workflow remains platform syntax only, extdeps.github.ci carries repository path facts, and gunbc.ci explicitly avoids a parallel Actions Workflow mirror until the WI-2 projection file exists (dsl/extdeps/github/ci.dag:7-11, dsl/gunbc/ci.dag:25-33). This matches the boundary/single-authority posture in the invariant index. chatgpt-review-d3316c8c-93d3-42…
  2. INVARIANTS.md + modeling-discipline.md — Compliant. The new coproducts are annotated instead of silently expanding the model: CancelInProgressSpec names a YELLOW scaffold plus dissolution trigger (dsl/extdeps/github/actions.dag:144-152), ConcurrencySpec makes queue: max + literal cancel-in-progress: true unrepresentable (dsl/extdeps/github/actions.dag:168-188), and GitHubActionsWorkflowExtension includes a GREEN ledger (dsl/extdeps/github/ci.dag:27-36). The external GitHub queue: max premise is supported by current GitHub Actions docs. GitHub Docs
  3. CODING.md — Compliant. The Rust changes preserve data + free-function shape: WITHOUT_PARSE_SURFACE_EXCLUDED_FIXTURE_PATHS is a narrow constant, and load_runtime_bootstrap_authorities now takes excluded_authority_paths and builds spec_iter as an explicit dependency/filter rather than hiding the exclusion in a global behavior branch (src/v3/compiler/src/bootstrap_regen_fresh.rs:109-118,124-142).
  4. TESTING.md — Compliant. No separate Rust test was added, but the diff’s verification surface is the regenerated bootstrap snapshots plus the named regen_bootstrap --verify ratchet in the PR-scoped receipt (docs/briefs/pb1-e-parse-surface-free-bootstrap-regen-p5-receipt.md:40-45). For this change class, that is the right level: the subject is bootstrap data/materialization, not a standalone behavior requiring a new imperative test. TESTING’s long-term direction also favors .dag/generated structural receipts over new Rust test surface. chatgpt-review-723e19a5-cb9d-4d…
  5. LOCKED DESIGN DECISIONS — Compliant. The diff does not alter a locked substrate shape or the pure-bootstrap target; it explicitly frames the remaining hand-Rust bootstrap regen as temporary and tied to T-PB-A / PB-Bootstrap-Process (docs/briefs/pb1-e-parse-surface-free-bootstrap-regen-p5-receipt.md:11-16,27-31). That is consistent with the thesis/pure-bootstrap direction that CI/build process and compiler surfaces move into .dag data. chatgpt-review-ed47e2b0-b9b6-4c…
  6. TRACKED vs UNTRACKED DEBT — Compliant. I found scaffolds, but they are tracked: CancelInProgressSpec has documentation, bounds, and a named typed-expression/projection dissolution trigger (dsl/extdeps/github/actions.dag:144-149); GitHubActionsWorkflowStemSegment documents the current NonEmptyStr bound and names the WI-2/projection or std-refinement trigger (dsl/extdeps/github/ci.dag:38-45); the parse-surface-free Rust exclusion has both a primary deletion trigger and a secondary shrink trigger (docs/briefs/pb1-e-parse-surface-free-bootstrap-regen-p5-receipt.md:27-38). No untracked temporary shape stood out.

2.5. Top-down PM intent review

Compliant. The highest-level intent is preserved: CI/build orchestration becomes modeled .dag data, but artifact emission is not hand-smuggled into the CI intent file. The diff says .github/workflows/ci.yml remains the sole live Actions transport for now, gunbc/ci.dag remains compiler-intent gates only, and WI-2 will introduce project_github_actions(..., runtime: WorkflowRuntime) as the future projection boundary (dsl/gunbc/ci.dag:25-33). That matches the thesis direction that meta-process modeling lives in .dag, while target/artifact projection remains structurally derived rather than maintained as parallel hand authority. chatgpt-review-ed47e2b0-b9b6-4c…

3. Verdict

APPROVE

I did not find a diff-cited invariant violation. The PR is scaffold-heavy, but the scaffolds are bounded, named, and tied to dissolution triggers; the layer split between CI intent, GitHub platform facts, repository path facts, and future WI-2 projection is deliberate rather than diluted.

@briansrls

Copy link
Copy Markdown
Contributor Author

Codex review #10139 (APPROVE) — verified

No actionable finding: verdict APPROVE matches current HEAD substrate/layering (extdeps path facts vs gunbc.ci intent, concurrency illegal-state split, P5 receipt + bootstrap_regen_fresh exclusion). No code change from this thread.

Merge readiness (worker): dashboard-ops reviews at HEAD 0b3878249: 3/2 approvals (claude, codex, cursor), no REQUEST_CHANGES, mergeable MERGEABLE, ready=false solely because checks_state: pending (GitHub v3 job still IN_PROGRESS on the current Actions run). Will gh pr merge 2745 --squash --delete-branch once dashboard shows ready: true and required checks are green per standing policy.

— sent from cool-carp-720

@briansrls
briansrls merged commit 3dbf5bd into main May 12, 2026
5 checks passed
@briansrls
briansrls deleted the session/cool-carp-720 branch May 12, 2026 12:14
briansrls added a commit that referenced this pull request May 12, 2026
…on 🟡 YELLOW (#2751)

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: canvas RATIFIED — §7 ratification dispositions

Director (zesty-bear-812) ratified option (c) at 2026-05-12T07:39:44Z
per PR #2751 comment (session msg_168005e1 to PM deep-wolf-155).

- Status header updated to RATIFIED
- §7 added with 4 ratification points + cascade implications:
  1. Expression sum-type at dsl/extdeps/github/actions.dag: RATIFIED
  2. Single OpaqueString variant + 🟡 YELLOW: RATIFIED
  3. Three-condition dissolution trigger: RATIFIED
  4. 5-site uniform migration: RATIFIED
- Cascade documented: cool-carp-720 (WI-2) Expression wrapping;
  stern-stag-854 (Slice 4-5) emit logic stays trivial; PR #2746 can
  reference ratified Expression substrate

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: site-count correction — 5→7 expression sites in actions.dag

Operator BLOCKING inline review on PR #2751 at :34 (briansrls
2026-05-12T07:45:24Z) flagged that actions.dag has Job.if_condition
+ RunStep.if_condition + UsesStep.if_condition (3 if_condition sites),
not 1. Same expansion applies to env: RunStep.env + UsesStep.env (2
sites), not 1.

Finding accepted. Actual migration scope is 7 sites total:
- Job.if_condition (:117)
- RunStep.if_condition (:154)
- UsesStep.if_condition (:163)
- RunnerSpec (new ExpressionRunner variant)
- ConcurrencySpec.group (:?)
- Step.with[k] (UsesStep:160)
- RunStep.env (:151) + UsesStep.env (:162)

Updates:
- §1 table: if_condition row shows 3 sites; env row shows 2 sites
- §1 narrative: "seven expression sites" with enumeration
- §2 (a/b/c) code samples: all 7 sites in option (c) sketch; Step
  carrier modeled with RunStep/UsesStep variants properly
- §3 reasoning point #1: explicit P2/P5 framing — leaving any
  if_condition/env site un-migrated creates hidden parallel authority
  (typed at one site, opaque at others) blocking P5 dissolution at
  un-migrated sites
- §5 / §6 / §7 site-count refs updated
- §7 site-count correction note: framing the expansion as
  site-count correction, NOT substrate-shape correction — ratification
  point #4's "single-authority for expression substrate" already covered
  ALL expression sites in actions.dag uniformly; 7-site scope is
  implementing-PR responsibility

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §4 dissolution target — template-string layer for extdeps fidelity

Operator BLOCKING #2 on PR #2751 at :214 (briansrls 2026-05-12T07:45:24Z):
the §4 dissolution target sketched a pure Expression AST, but GH Actions
expression-bearing scalars are template strings with alternating literal-
text and ${{...}} segments (e.g., concurrency.group:
${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }}).
A pure-AST terminal shape under-models what the platform actually parses,
violating INVARIANTS.md P1 (modeling faithfulness).

Finding accepted. §4 dissolution target corrected to two-layer shape:

  Expression
    = OpaqueString(String)
    | Template(List<TemplateSegment>)

  TemplateSegment
    = TextSegment(String)
    | ExpressionSegment(ExpressionAst)

  ExpressionAst = Literal | Var | BinOp | Func | Index (etc.)

This is extdeps-faithful: mirrors the platform's actual parse structure
(template-string layer over expression-AST layer). Pure-literal /
pure-expression / mixed scalars all collapse cleanly into the segment
list.

Original sketch preserved as authoring-evolution record; corrected shape
supersedes.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §6 Q#1 RESOLVED — sum form, not record (per BLOCKING at :258)

Operator BLOCKING #3 on PR #2751 at :258 (briansrls 2026-05-12T07:45:24Z):
§6 open question #1 incorrectly treated record form and one-arm sum as
equivalent. A record form (type Expression { value: String }) does NOT
preserve:
- Single-arm pattern-match property on consumers (record access
  projects to .value as String; no tag to match)
- Single-edit second-variant dissolution path (record → sum is a
  carrier-shape change, not a one-line declaration edit; every
  consumer must be rewritten to switch from .value access to
  pattern-match)

This breaks Practice 4 (coproduct dissolution) and P5 (Progress Is
Dissolution) — the dissolution receipt the YELLOW classification
relies on assumes the dissolution is cheap; record form makes it
expensive.

Q#1 resolved inline: Expression lands as a one-arm sum
(type Expression = OpaqueString(String)), NOT a record. This was
implied by §3 reasoning point #4 ("Pre-empts the type-alias trap")
which applies equally to record-form aliases, but the §6 framing
treated both as admissible — corrected.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: add CI workflow emitter-dispatch canvas (#2746)

* docs: add CI workflow emitter-dispatch canvas

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* docs: align workflow emitter canvas with substrate comparison

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* docs: keep InlineGunbc out of initial target enum

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* docs(r3): §1.8 acceptance-aggregator pattern scaffold (pilot) (#2748)

* docs(r3): expand R3 lanes to 12 + lens-framework invariant + analysis findings

User directive 2026-04-30: "nothing can be deferred past R3 - we have to
readjust R3 if something is missing." PM-driven audit + Director ratification.

R3 lane expansion (10 → 12):
- T-V2-Retirement (NEW; PB Manager continuation): src/v2/ retirement
  cascades from T-FixedPoint + T-LensProducer-Retirement; structurally
  cheap to pull in. Gates: v2_oracle_no_remaining_test_consumers +
  v2_directory_deleted.
- T-Free-Consequences-Demonstration (NEW; Verification Manager): 10-gate
  TestClaim suite operationalizing thesis "free consequences" framing.
  Auto-parallelism + auto-memoization + cross-target opt + space-bound CX.
  Loop-iteration parallelism: sequential default + opt-in via
  Lens<Iteration-Independence> (zero-heuristic; same shape as
  Lens<Bind-Independence>).

Priority corrections folded into existing lanes (no new lanes):
- C1 (T-Tier3-Dissolution sub-gate): tier3_mirror_dissolution_perf_within_budget
  with thresholds <=2x median, <=5x p99 (cargo bench fixtures per retired
  mirror).
- C2 (Substrate continuation, T-Anthropic-Wire scope expansion):
  ProviderTypedWire<P> carrier extracted IN R3 (path (a) commit; drops the
  prior 6-month elapsed-time check exactly per user directive).

design-lens-framework.md amendment:
- Lens.read MUST depend only on (Node, Behavior) pair, not external state.
- Locks memoizable shape; runtime memoization becomes auto-memoization free
  consequence instance (T-Free-Consequences-Demonstration).

ROADMAP.md additions (### Post-merge debt (2026-04-30 analyses)):
- 4 novel findings from paired exploratory + reflective analyses
  (gpt-5-5-pro 991114f / gpt-5-5-thinking ad016c5):
  * Duplicate record-literal fields silently dropped (highest-value bug)
  * ValueBody Rust<->.dag mirror drift; no isomorphism gate
  * FieldMap duplicate-free invariant lost in .dag mirror
  * Operator inference fabricates (T,T)->T for non-algebra LHS
- 8 reflective-analysis priority corrections folded into R3 trajectory
- 2 stale rows marked RESOLVED (repeat_string + lower_fn_body re-derive)

Routed to R3 Mgrs via inbox dispatches (#1130 / #1131 / #1133 / #1276 / #846).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): reframe Rust<->.dag isomorphism as producer-first

cool-crab-614 PR #1324 research reframed the proposal: missing substrate
is a reflected-Dag query/report PRODUCER (Lens<DagShapeReport>), not a
new predicate variant. RustDagIsomorphism becomes a CONSUMER (TestClaim
comparing two DagShapeReport outputs via BinaryDimensionReportEquals),
eliminating parallel-authority risk.

Reflection-aware modifiers for unified BinaryDimensionReportEquals now
cover 4 surfaces: TC1 eta-equivalence + TC2 strategy-order + TC3
evaluation-step + shape-report (reflected-Dag query).

Single substrate-introduction; multiple consumers via reflection-aware
modifiers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): fix lower_fn_body row citation per #1319 review

PR #1319 review (cursor 9d2dffb) flagged that the RESOLVED note cited
`src/v3/compiler/src/lower.rs:61670-61688` but lower.rs is only 7919
lines. Original line citations referenced the analysis snapshot's
aggregate-numbering scheme, not live file.

Verified live state: `lower_fn_body_into_existing_decl` symbol does NOT
exist in current lower.rs; equivalent path is `lower_fn_item_expr_body`
(:4410+); non-Arrow arm at :4433-4451 reports
`Diagnostic::ResolveError` with explicit invariant-violation message
("violated lowering invariant: seed_function_signatures_phase did not
produce an Arrow connective for this Fn") and returns outer_scope.
That IS the fail-closed shape the original row asked for; resolution
note now correctly cites live behavior.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): resolve v2-retirement contradiction per #1319 review

PR #1319 review (codex a9a9894) flagged contradiction: T-V2-Retirement
added as R3 lane (line 100) but Compromises table (line 165) still
listed v2 retirement as Post-R3 operational cleanup. INVARIANTS P1
"Documentation Describes Live State" violation.

Fix: strikethrough the post-R3 entry; explicitly note migration into
R3 as T-V2-Retirement lane per 2026-04-30 user directive "nothing can
be deferred past R3." Single authoritative placement; cross-link to
Lane structure §11.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* docs(r3): aggregator pattern — coercion table + precondition + exclusion rules

Addresses BLOCKING #2748 (briansrls inline at L71): live §1.8 uses 7 status
values, not 3 (PASSING, SATISFIED-BY-CONSTRUCTION, CONSUMER_LANDED, DECLARED,
R3-LOAD-BEARING, HELD-CANVAS-DEFERRED, DEFERRED). The 3-value lattice meet
was not machine-checkable as written.

- Coercion table: SATISFIED-BY-CONSTRUCTION → PASSING; INTEGRATION_RECEIPT
  partial-slice → CONSUMER_LANDED; identity for the 3 lattice values.
- Precondition rule: bare R3-LOAD-BEARING is scope-metadata, not closure
  progress; constituents with that status are not aggregator-ready until
  cell inlines closure-progress (e.g., 'R3-LOAD-BEARING — DECLARED').
- Exclusion rule: DEFERRED + HELD-CANVAS-DEFERRED MUST NOT appear in any
  aggregator's depends_on: per §1.5 honest-close arithmetic.
- Cluster F candidate reframed: NOT aggregator-ready at HEAD because rows
  #81/#82/#83/#95 carry bare R3-LOAD-BEARING; precondition fix required
  before pilot. Cluster M / K / V2-Retirement candidates similarly subject
  to precondition check at pilot time.
- Invariants P2 cleanliness note: coercion table + precondition + exclusion
  are themselves a single derivation authority; no parallel authority for
  closure progress.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): cascade ci_yml_deleted → ci_yml_hand_authority_dissolved rename

Per PM cascade (PR #2744 commit 19a1d8d absorbing briansrls BLOCKING
on line 32): file artifact presence is orthogonal to hand-authority
dissolution. YamlStatic / BinaryShim / PythonShim all require some
.github/workflows/ci.yml for GH Actions trigger discovery; P5 / Pure
Bootstrap dissolves authority, not file presence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): relocate aggregator pattern from §1.8 to §1.9 per codex P2 finding

Addresses codex REQUEST_CHANGES /api/reviews/9982 on PR #2748: putting
aggregator rows directly in §1.8 alongside their constituents violated
INVARIANTS P2 single-authority — even with "derived not hand-set" prose,
the row shape didn't structurally prevent treatment as a closure
obligation, and the side-taxonomy of "does not participate in §1.7
corpus rules" was a P2 boundary-discipline violation inside the
canonical ledger.

Restructured:
- Aggregators relocated to a NEW §1.9 section (separate table)
- Distinct ID namespace: V1, V2, ... (NOT numeric §1.8 row IDs)
- Different table columns (View ID / View Name / Cluster Lane /
  depends_on: / Derived Status / Notes) to make visual distinction
  obvious
- depends_on: references §1.8 row #s by foreign-key style
- Derived Status rendered as <DERIVED> in committed text; never stored
  as snapshot (per feedback_no_snapshot_integers_in_briefs)
- §1.8 "97 enumerated / 96 R3-load-bearing" arithmetic preserved
  unchanged; §1.9 entries do not appear in that arithmetic
- Coercion table + precondition + exclusion rules carried forward
- Cluster F precondition catch (rows #81/#82/#83/#95 carry bare
  R3-LOAD-BEARING) preserved

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): annotate R4-carve citation with supersession marker

Fixes CI failure on PR #2748: scripts/check-r4-carve-dissolution-discipline.sh
flagged the coercion-table row for R3-LOAD-BEARING which mentioned 'R4-carved'
without a supersession annotation. Reframed to cite carve-promotion-IN-R3
2026-05-09 + DISSOLVED status per Director ratification gunbc#846.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): correct #83 characterization + add filename note

Per cursor APPROVE_WITH_COMMENTS /api/reviews/10000 on PR #2748:

- Row #83 (lens_capability_register_zero_proxy_zero_stub) was incorrectly
  listed alongside #81/#82/#95 as carrying "bare R3-LOAD-BEARING". The
  authoritative ledger has #83 reading "DECLARED — full scope IN R3
  (carve-promotion-IN-R3 2026-05-09)", which inlines closure-progress
  alongside scope-metadata and already coerces to DECLARED under the
  precondition rule. Reframed #83 as a positive counter-example showing
  the inline-pattern #81/#82/#95 still need to adopt.

- Added top-of-doc filename note explaining the §1.8 vs §1.9 mismatch:
  filename retained for review-thread anchor stability; substantive
  section is §1.9.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add sunset condition for aggregator pattern pilot doc

Per cursor /api/reviews/10013 optional tighten: PILOT scaffold needs a
single checkable sunset to satisfy P5 scaffold-posture discipline.
Sunset: doc retires when docs/r3-program-plan.md contains §1.9 per the
specified table shape AND at least one §1.9 view entry is live in the
ledger.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add composite-status coercion rule (CONSUMER_LANDED + PASSING)

Addresses briansrls BLOCKING inline at L66 on PR #2748: coercion table
omitted live §1.8 composite forms like 'CONSUMER_LANDED + PASSING'
(~25 instances in the ledger, including candidate Cluster M constituent
#86 program_generator_carrier_landed).

Added:
- Explicit row for 'CONSUMER_LANDED + PASSING' → PASSING
- General composite rule '<earlier> + <later>' → coerce to <later>
  (rightmost component; conjunction-of-progression-stages semantics);
  covers future composite forms not enumerated.

This makes #86 view-ready under the precondition rule (coerces cleanly
to PASSING).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag) (#2747)

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* docs: add CI workflow emitter-dispatch canvas

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* docs: add T-CI-WAD slice 4 skeleton

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* docs: clarify T-CI-WAD projection sketch

* docs: align T-CI-WAD prep with c-refined shape

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* docs(r3): T-WAD substrate-shape comparison canvas — gate #56 (#2749)

* docs(r3): flip §1.8 #85 forall_exists_quantifier_substrate_landed to CONSUMER_LANDED + PASSING

PR #2647 (vivid-dove-106 / Cluster M Phase 1a) merged carriers into src/v3/std/verification.dag at HEAD; ledger row was drifted DECLARED. Per post-merge ledger-receipt sync discipline (Director-ratified at gunbc#828 c#4415884211).

Caught by Debt-Paydown PM ledger-sync check — thanks silent-ram-834.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): downgrade §1.8 #85 to DECLARED per codex BLOCKING + row #17 precedent

Prior CONSUMER_LANDED + PASSING flip overstated the gate per INVARIANTS §P2 strict reading: carriers + hand-written ratchet ≠ generated consumer proof. Mirrors row #17 (numeric_abstract_carriers_landed) shape: carrier substrate landed, hand-written ratchet noted, CONSUMER_LANDED deferred to generated consumer + SuiteClaim wrapper migration + V Mgr #87 runner consumer.

Sibling row #86 carries same overclaim risk via PR #2645 precedent — separate amendment if Director rules.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: T-WAD substrate-shape comparison canvas (gate #56)

Mgr-tier comparison canvas surfacing three substrate-shape options for
gate #56 ci_workflow_modeled_as_dag under FULL R3-close elevation:

- (a) PR #2736 provider-neutral CIWorkflowDag (semantic-only)
- (b) WI-1 PR #2746 actions.dag-concrete + EmissionTarget? (transport-only)
- (c) Hybrid — CIWorkflowDag as semantic source + Workflow.emission_target
  as transport-artifact selector + projection function project_github_actions:
  CIWorkflowDag -> Workflow as the structural fold connecting them

§0 grep-verifies PR #2736 body claim ("hand-authored GitHub Actions transport
copy was removed") against actual diff: actions.dag Workflow/Job/Step
carriers at :21/:110/:147 intact; PR adds CIWorkflowDag without removing
actions.dag carriers, leaving dual-authority unresolved at HEAD.

§5 recommends option (c) for Director ratification on:
- single-authority per concept layer (gate-dependency at gunbc.ci;
  transport at extdeps.github.actions) per MODELING.md M9
- decoupled cost-of-change axes (new provider vs new emission target)
- preserves both already-authored PRs' substrate contributions
- aligns with docs/design-emission-model.md single-emitter discipline

Authority: PM relay msg_a945b141 (deep-wolf-155) routing Director
msg_34e9a381 substrate-shape question per
feedback_substrate_shape_belongs_in_mgr_canvas.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7 addendum — INVARIANTS P1 reframes (c) to (c-refined)

BLOCKING inline review on PR #2746 (briansrls c#4427988541) flagged
that adding EmissionTarget to dsl/extdeps/github/actions.dag puts a
gunbc emission-policy fact into the GitHub Actions platform model,
violating extdeps fidelity and INVARIANTS P1.

§7 accepts the finding (structurally correct per actions.dag header
:1-12 platform-vs-CI-logic discriminator), disqualifies §1 option (b)
as-authored, partially invalidates §1 option (c) as-authored (the
two-layer concept-layering argument STILL holds; only the EmissionTarget
placement on extdeps fails P1).

§7.3 surfaces option (c-refined): EmissionTarget lives in gunbc/ci.dag
as a sum type + parameter to project_github_actions(ci_workflow_dag,
target) -> Workflow. extdeps.github.actions.Workflow is unmodified.
Pinned Workflow values for emission validation live in gunbc namespace.

§7.5 revises ratification asks: PR #2746 disposition shifts from
"framing-narrowing" to substantive substrate retraction on the field-
placement decision (sum-type shape stands; placement relocates).

§7.6 distinguishes (c-refined) from PM-proposed alternatives:
- not PM(b) [EmissionTarget on CIPipeline] — same M9 join-cost as
  PR #2746 §3 Option B
- not PM(c) [WorkflowEmission wrapper] — same sibling-decision cost
  PR #2746 §3 Option C already rejected
(c-refined) expresses emission-target choice at the projection
invocation (per docs/design-emission-model.md: emission is structural
projection, choice is property of the call not the value).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §8 retraction — derive Workflow from projection, not separate authority

codex REQUEST_CHANGES on PR #2749 (review 9970) flagged that option (c)
as authored proposed both a projection function CIWorkflowDag -> Workflow
AND a separately hand-declared Workflow value the emitter "validates
against" as a pinned target — INVARIANTS P2 / modeling-discipline.md
Practice 5 dual-authority condition.

Finding accepted. §8 retracts the pinned-Workflow-as-modeled-authority
framing; in-place edits applied to §1 (option (c) intro), §4 (S0
sequencing), §5 (ratification ask #5), §7.3 (WI-2 placement), §7.5
(revised recommendation).

Replacement framing: the only Workflow value in modeled authority is
the projection function output, structurally derived from a single
source. WI-2's gunbc_ci_yml_workflow becomes a name binding to the
derived result (data gunbc_ci_yml_workflow: Workflow =
project_github_actions(ci_workflow_dag, YamlStatic)), not an
independent declaration. Byte-level regression fixtures live in
tests/, not dsl/, and are not part of modeled authority.

Layering argument unchanged: gate-dependency at gunbc.ci.CIWorkflowDag;
platform transport at extdeps.github.actions.Workflow (unmodified);
emission policy in gunbc namespace; artifact derived from single source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: cite feedback_extdeps_header_discriminator_before_field_placement

Per PM relay msg_72e2ab50: Director memorialized actions.dag:1-12
discriminator rule as feedback_extdeps_header_discriminator_before_field_placement.
Add citation in §7's discriminator block for audit trail.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: cite P2 (Boundary Discipline) not P1 for single-authority

gpt-5.5-pro APPROVE_WITH_COMMENTS review 9972 caught that the
single-authority / "every fact lives in exactly one place" principle
is INVARIANTS.md P2 Boundary Discipline, not P1. P1 is Modeling
Faithfulness.

Operator BLOCKING quote at §7 invoked "P1" verbatim; both principles
are in play:
- P2 because emission-policy authority must live in exactly one place
  (gunbc/ci.dag), not split across extdeps and gunbc
- P1 because placing gunbc-policy state on an extdeps carrier makes
  the carrier no longer faithful to its header's "platform facts
  only" claim

§7.1 prose updated to explicitly distinguish the two principles and
note that subsequent single-authority references cite P2.
§7.4 table row relabeled "INVARIANTS P2 (Boundary Discipline / single
authority)".
§7.5 ratification ask #2 cites P2 + P1.
§7 heading updated to "INVARIANTS P2/P1 BLOCKING reframes (c)".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: classify EmissionTarget coproduct per Practice 4 (§7.3.1)

BLOCKING inline review on PR #2749 at line :573 (briansrls
2026-05-12T07:04:15Z): proposed EmissionTarget 4-variant coproduct
landed without 🟢/🟡/🔴 dissolution classification, violating
modeling-discipline.md Practice 4 (coproduct dissolution).

Finding accepted. §7.3.1 added classifying EmissionTarget as
🟡 YELLOW (scaffold) with full reasoning across all four dissolution
patterns:
- Pattern 1 (fact placement): N/A — empty payloads
- Pattern 2 (variant-is-data): blocked by closed-set guardrail
- Pattern 3 (algebraic form): N/A — not std/ algebraic operations
- Pattern 4 (dimensional): live dissolution path; ~2-3 axes
  (target_language, requires_shim, runtime_executes) plausible but
  not yet forced at four variants

YELLOW not GREEN: Pattern 4 plausibly works; closing the door would
be wrong. YELLOW not RED: dissolving prematurely without consumer-
side pressure risks landing wrong axes (requires_shim partially
redundant with target_language at current variants).

Named dissolution trigger (per YELLOW requirements): (a) fifth
target landing that breaks the four-way axis, OR (b) consumer needing
single-dimension pattern-match, OR (c) Slice 4/5 implementation
surfacing an unpredicted axis. Any forces dimensional record shape.

Ledger note: classification is canvas-level; implementing PR (WI-2
re-brief per §5/§7.5 ask #4) MUST carry the same classification +
trigger as a // 🟡 YELLOW (scaffold) comment on the type declaration
citing this canvas §7.3.1.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: canvas RATIFIED — §9 ratification dispositions

Director (zesty-bear-812) ratified option (c-refined) at
2026-05-12T07:04:18Z per PR #2749 comment (session msg_4f7f536d
to PM deep-wolf-155). Updates:

- Status header changed to RATIFIED with ratification authority
  citation
- §9 added with all 5 ratification asks dispositioned:
  - (c-refined) substrate-shape: RATIFIED
  - PR #2746: AMEND (4 specific changes for still-heron-763)
  - PR #2736 body: SATISFIED prior
  - PR #2745 WI-2: SCOPE EXPANSION APPROVED, PM authors re-brief
  - S1 projection function: NEW §1.8 GATE (project_github_actions_landed,
    substrate-shape family); aggregator pilot row #56+4→#56+5
- Downstream cascade documented per Director directive

Director attributed feedback_extdeps_header_discriminator_before_field_placement
discipline rule to the §7+§8 self-correction trajectory.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: inline SUPERSEDED banners on §1(c)/§2.3/§3/§4/§5

codex BLOCKING review 9986 at sha 38c28cd flagged that §2.3/§3/§5
still contain the now-overturned option-(c)-as-authored framing
(EmissionTarget on extdeps.Workflow + hand-declared pinned Workflow).
For a RATIFIED canvas, leaving those sections unmarked materially
states the wrong substrate shape — readers would have to read through
to §7/§8/§9 to discover the supersession.

Finding accepted. Inline SUPERSEDED banners added at the top of:
- §1 Option (c) sub-section: points to §7.3/§7.4/§8/§9 for current shape
- §2.3 Option (c) evaluation: flags the "emission validates declared
  Workflow against projection" sentence as the dual-authority condition
  §8 retracts
- §3 WI-1 assumption-breakage: OVERTURNED bullets explicitly listed
  (placement, "Workflow chooses target" framing, framing-narrowing
  disposition)
- §4 Slice sequencing under (c): SUPERSEDED in part — structure
  remains valid under (c-refined); placement-specific descriptions
  overturned by §7/§8; WI-2 scope larger than §5.4 implied per §9 ask #4
- §5 Recommendation: all three positions (extdeps placement,
  framing-narrowing PR #2746 disposition, pinned-Workflow validation
  target) OVERTURNED; current recommendation is (c-refined) per §7.5+§9

Earlier framings preserved as canvas-evolution record (showing
self-correction trajectory through §7+§8), but each affected section
now flags its own superseded status without requiring a full-doc read.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §6 Q#2 RESOLVED banner — overturned superseded Workflow framing

cursor APPROVE_WITH_COMMENTS review 10001 (non-blocking) noted that §6
open question #2 still partly explained the projected signature via
"PR #2746 places the field on Workflow", which contradicts §7.3
(c-refined) where extdeps.github.actions.Workflow is frozen unmodified.

Fix: add inline RESOLVED banner at §6 head pointing to §7.3 + §9; rewrite
Q#2 entry to flag the superseded framing inline — the parametric
signature was the right answer regardless of placement, but the rationale
over-attributed to a placement that no longer stands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: inline 🟡 YELLOW checkpoint at §7.3 EmissionTarget declaration

Operator BLOCKING inline review on PR #2749 at :657 (briansrls
2026-05-12T07:58:34Z): the §7.3 code block declaring type
EmissionTarget lacked the inline 🟢/🟡/🔴 classification annotation
required by modeling-discipline.md Practice 4 "any new enum with
N ≥ 2 variants must have a checkpoint comment naming its classification."

The classification reasoning exists in §7.3.1 prose section, but the
declaration site itself was missing the checkpoint comment, which is
the form Practice 4 requires.

Fix: add inline 🟡 YELLOW (scaffold) comment block above the type
declaration citing §7.3.1 for full reasoning + the three-condition
dissolution trigger + likely Pattern 4 dissolution path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7.3.2 Shape A/B clarification — EmissionTarget names realization modes

Operator BLOCKING inline review on PR #2749 at :657 (briansrls
2026-05-12T07:58:35Z): YamlStatic variant of EmissionTarget would
"make a Shape B CI YAML artifact mode an emission target despite
THESIS Shape A/B requiring YAML artifacts to be generated by .dag
user programs, not compiler emission targets."

Per THESIS:215-216, Shape A = compiler language targets (compiler
emits directly); Shape B = user-program artifacts (YAML, Terraform,
K8s, etc. — emitted by .dag programs walking typed values, NOT
compiler render targets). YAML for ci.yml is Shape B; gunbc
doesn't have a YAML emission target.

Finding accepted as naming-and-framing concern, not substrate-shape
concern. Added §7.3.2 clarifying:

- EmissionTarget names a REALIZATION MODE selector, not a parallel
  compiler emission target
- YamlStatic = Shape B (.dag program renders YAML from Workflow)
- BinaryShim = Shape A binary + Shape B YAML shim wrapper
- PythonShim = Shape A Python + Shape B YAML shim wrapper
- InlineGunbc = Shape A (gunbc runtime as host)

No substrate retraction: variants, YELLOW classification, dissolution
trigger, gunbc-namespace placement, parametric signature all stand.
Naming consideration noted (WorkflowRealizationMode would carry less
Shape-A baggage), but renaming forces re-ratification without
corresponding substrate change — keep name, document the mapping at
declaration site per §7.5 ask #4 implementation PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: fix §9 ask #5 slice/gate name — Slice 8 ci_yml_dissolved, not Slice 5 ci_yml_deleted

gpt-5.5-pro REQUEST_CHANGES on PR #2749 sha f5b57e7 (review 10037)
caught that §9 ratification ask #5 wrote the projection-function gate
as "discrete from Slice 5 (ci_yml_deleted, state-check)", but per the
canvas's own §1 (Director-ratified gate-set) and §4 Slice sequencing:
- Slice 5 = BinaryShim emitter (workflow_emission_target_toggle_proven)
- Slice 8 = ci.yml dissolution (gate name: ci_yml_dissolved)

The conflation could mislead workers updating PR #2748 to wire the new
project_github_actions_landed gate against the wrong slice/gate.

Fix: §9 ask #5 now reads "discrete from Slice 8 ci_yml_dissolved",
matching the canvas's earlier authoritative gate-set + §4 sequencing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: §5.5 inventory audit — 7→22 expression-capable fields

codex BLOCKING (review on sha 4f41aeb) + operator BLOCKING inline at
:315 (2026-05-12 ~09:12Z): site inventory was keyed to ci.yml examples
not actions.dag schema + GH Actions context-availability docs.
Under-modeling the platform expression-capable surface by ~15 sites.

Finding accepted as substantive scope correction. Added §5.5 with
full audit table against actions.dag HEAD + GH Actions docs:

Total expression-capable surface: 22 fields across Workflow / Job /
RunStep / UsesStep / ConcurrencySpec / RunnerSpec. The 7-site
enumeration was the ci.yml-keyed minimum subset; the
actions.dag-keyed audit extends to 22.

§5.5.1 sets migration rule: ALL expression-capable fields migrate
uniformly under (c). Per-field opt-in produces hidden parallel
authority (P2/P5 violation). Implementing PR audits against actions.dag
HEAD + GH Actions context-availability docs and migrates any
additional sites surfaced.

§5.5.2 surfaces typed-field expression semantics as new substantive
question (§6 Q#4) — timeout_minutes/continue_on_error/cancel_in_progress
are typed fields where GH Actions string-coerces expressions. Three
candidate shapes (wrap / TypedOrExpression sum / defer); Director-tier
choice.

§5.5.3 retains §1/§2 7-site framing as ci.yml-keyed reference;
substrate-shape ratification covers expanded 22-site scope per §5.5.1
migration rule.

§6 Q#2 sequencing updated to "22 expression-capable fields"; new Q#4
adds typed-field semantics question.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: update PR #2749 cross-link — EmissionTarget → WorkflowRuntime

Per PR #2749 commit 575eb7e (rename EmissionTarget → WorkflowRuntime
to resolve P2 name-collision with src/v3/SELF_HOSTING.md:609 Shape-A
EmissionTarget), update the single cross-reference in §7 here to match
the new name. Substantive content unchanged — orthogonal-axes argument
still holds.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §5.5.1 — split 22 sites into 13 string + 7 typed-field + 2 enum-ext

codex REQUEST_CHANGES on PR #2751 review 10083 (sha presumably 0cc2c28e
or 28d503c): §5.5.1 said "ALL 22 expression-capable fields migrate to
Expression" but §5.5.2 / §6 Q#4 left typed-field shape (Int?/Bool sites)
as an open Director-tier question. Implementer following §5.5.1 would
author the wrap-to-Expression shape immediately while §5.5.2 says hold.

Finding accepted. §5.5.1 split into three classes:

- 13 string-typed sites — uniform String→Expression migration, in scope
  for §7.5 ask #4 prereq PR
- 7 typed-field sites (timeout_minutes/continue_on_error/
  cancel_in_progress) — HOLD until §6 Q#4 ratifies wrap/sum/defer
- 2 enum-extension sites (RunnerSpec, UsesStep.uses) — new variant
  added to existing sum/struct, in scope for §7.5 ask #4 prereq PR

In-scope for substrate-prereq PR: 13 + 2 = 15 sites. Out-of-scope
(deferred): 7 typed-field sites.

§5.5.1 now non-contradictory with §5.5.2 / §6 Q#4: implementer reading
§5.5.1 migrates 15 sites; the 7 typed-field sites explicitly HOLD with
a named trigger (§6 Q#4 ratification).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §5.5 inventory expansion — add Workflow.name + Job.name (22→24 sites)

Operator BLOCKING on PR #2751 at :365 (briansrls 2026-05-12T10:12:15Z):
the string-typed migration class omitted Job.name: String?; GH Actions
context-availability table lists jobs.<job_id>.name as expression-capable.
Same applies to Workflow.name (workflow name supports expressions).

Audit gap fixed. §5.5 table adds:
- Workflow.name: String (:22) — string-typed expression-capable
- Job.name: String? (:112) — string-typed expression-capable

Counts updated:
- Total expression-capable: 22 → 24 sites
- String-typed class: 13 → 15 sites
- In-scope for prereq PR: 15 → 17 sites (15 string + 2 enum-extension)
- Out-of-scope (typed-field HOLD): 7 sites (unchanged)
- Under-modeling delta: 15 → 17 sites (ci.yml-keyed 7-site enumeration
  missed 17 sites in actions.dag schema)

§5.5.1 enumerated list of string-typed sites adds Workflow.name + Job.name.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: §5.5 — remove UsesStep.uses (literal-only per GH workflow-syntax)

Operator BLOCKING on PR #2751 at :381 (briansrls 2026-05-12T10:12:15Z):
classifying UsesStep.uses as expression-capable invents platform
capability — GH Actions workflow-syntax treats uses: as a literal
action location; the context-availability table does NOT list
jobs.<job_id>.steps.uses. Modeling it as expression-capable would
violate INVARIANTS.md P1 modeling faithfulness.

Verified against GH Actions docs (workflow-syntax + context-availability):
uses: is a literal action ref resolved before workflow expressions
evaluate.

Finding accepted. Removed UsesStep.uses from §5.5 inventory + struck out
the row + removed planned ExpressionActionRef variant from
enum-extension class.

Counts updated:
- Total: 24 → 23 sites
- Enum-extension class: 2 → 1 site (RunnerSpec only)
- In-scope for prereq PR: 17 → 16 sites (15 string + 1 enum-ext)
- Under-modeling delta: 17 → 16 sites
- Typed-field HOLD class: 7 sites (unchanged)

§5.5.1 enum-extension block now explains why UsesStep.uses was
removed for audit trail.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7 ratification ask #4 — reflect §5.5 expanded scope (16 in-scope, 7 HOLD)

Operator BLOCKING on PR #2751 at :543 (briansrls 2026-05-12T10:12:15Z):
§7 ratification dispositions still referenced the 7-site enumeration from
the original ratification framing, while §5.5 expanded the audit to
23 sites. Downstream implementation reading only §7 would preserve
opaque-string authorities at the non-§7-enumerated sites — P2/P5
violation by structural drift.

Fix: §7 ratification point #4 rewritten to cite §5.5 audit set + 16
in-scope sites + 7 typed-field HOLD class with named trigger.

Site-count correction note expanded from single-event to cumulative
correction sequence documenting all 4 BLOCKING-driven expansions
(5→7→22→24→23). Audit trail preserved; the (c) substrate-shape
ratification covers all 23 expression-capable sites uniformly per
"single-authority for expression substrate" principle — implementing
PR migrates 16 immediately, 7 typed-field sequenced post §6 Q#4
ratification.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 expand to MatrixStrategy carriers (23→28 sites; audit-methodology note per codex review 10128)

Cross-product of GH context-availability table × actions.dag carriers adds
MatrixStrategy.{dimensions,include,exclude,fail_fast,max_parallel}.
Updated counts: 28 total / 18 string-typed / 9 typed-field / 1 enum-ext;
19 in-scope for prereq PR, 9 HOLD for §6 Q#4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 remove Workflow.name (literal-only per GH context-availability; run-name is expression-capable key and not currently a Workflow field) — operator BLOCKING :274

28→27 total, 18→17 string-typed, 19→18 in-scope.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 add DispatchInput.default (operator BLOCKING :298) — workflow_call/workflow_dispatch input defaults per GH context-availability

27→28 total, 17→18 string-typed, 18→19 in-scope. MatrixStrategy already present per commit 9c1f0a1.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): status-block migration scope = 19 in-scope + 9 HOLD (was '5 sites uniform') — operator BLOCKING :7

Aligns top-of-file status with §5.5 / §7 ratified scope: 28 total / 18 string-typed + 1 enum-ext = 19 in-scope for prereq PR / 9 typed-field HOLD on §6 Q#4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5.1/§7/audit-trail count reconciliation (28/18/19/9) — cursor review 10134

Sweep stale internal counts: 23→28 site totals, 15→17 string-typed in audit blockquote, 5→9 typed-field, 16+7→19+9 deferred. Added correction step 5 to audit trail covering MatrixStrategy + DispatchInput.default additions and Workflow.name removal. Aligns §5.5.1, §5.5 audit-trail blockquote, §7.5 ask #4 with §5.5 audit totals.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): fix 'seven sites-already-migrated' (→19) + P5/modeling-discipline citation drift — cursor review 10145

:146 + :231-233: dissolution-cost wording updated from pre-§5.5 '7 sites' to post-audit '19 sites + 9 typed-field once §6 Q#4 resolves'.
:289-291: scaffold-arm sunset-milestone citation moved from INVARIANTS P5 (which mandates checkable dissolution trigger) to modeling-discipline.md Practice 4 (home of the scaffold-comment convention).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5.1 derivation discipline + add MatrixStrategy carriers to class lists; §6 Q#5 (DispatchInput carrier-split) + Q#6 (RunnerSpec runs-on grammar) — codex BLOCKING 10150

(1) §5.5.1 lists now explicitly enumerate MatrixStrategy carriers per class: dimensions/include/exclude in string-container (18 total), fail_fast/max_parallel in typed-field HOLD (9 total). Added explicit derivation-from-§5.5-table discipline note. Cross-check 18+9+1=28 ✓.

(2) §6 Q#5: shared DispatchInput collapses workflow_call vs workflow_dispatch expression-context-availability axes; carrier-split question surfaced (Director-tier sequencing relative to Slice 4 prereq PR).

(3) §6 Q#6: RunnerSpec under-models runs-on grammar (scalar/array/object + expressions at multiple positions); §2 (c) ExpressionRunner only covers scalar case. Carrier-split question surfaced.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(r3): DispatchInput.default → carrier-split-blocked class (workflow_dispatch is literal-only per GH context table) — operator BLOCKING :369

GH context-availability marks only on.workflow_call.inputs.<id>.default as expression-capable; on.workflow_dispatch.inputs.<id>.default is literal-only. Migrating the shared DispatchInput.default to Expression would invent workflow_dispatch capability (P1 violation).

§5.5 table row updated: ✗ split capability; §5.5.1 adds new 'carrier-split-blocked sites (1)' class; counts now 17 string-container + 9 typed-field-HOLD + 1 enum-extension + 1 carrier-split-blocked = 28 ✓. In-scope for prereq PR: 19→18. §6 Q#5 sharpened from 'sequencing question' to 'BLOCKED until carrier-split lands'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 Job.runner audit row + §5.5.1 enum-extension class flag partial-coverage (array/object/label-element expressions unmodeled) — operator BLOCKING :345

§2 (c) ExpressionRunner covers only whole-runs-on scalar-expression case. Array form (mixed literal/expression elements) and object form (group/labels expressions) require §6 Q#6 RunsOn carrier-split. Scalar-only case stays in §7.5 ask #4 prereq PR; array/object defer to §6 Q#6 resolution.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
… name-collision) (#2756)

* docs: rename EmissionTarget → WorkflowRuntime in emitter-dispatch canvas

Follow-on rename PR for docs/design-ci-workflow-emitter-dispatch.md
(merged to main via PR #2746 commit 2878c5d) to resolve the
INVARIANTS P2 name-collision identified on PR #2749 at :666:

src/v3/SELF_HOSTING.md:609 declares the canonical Shape-A carrier:

  type EmissionTarget {
    language: LanguageSpec
    rendering: RenderingSpec?
  }

The merged PR #2746 content used the same name (EmissionTarget) for a
CI realization-mode selector — literal name collision, two different
things named the same.

Cascade context (all in-flight PRs already rename-applied):
- PR #2749 (this Mgr's substrate-shape canvas) — commit 575eb7e
- PR #2751 (this Mgr's expression-substrate canvas) — commit 28d503c
- PR #2744 (PM scope-doc + briefs) — commit d25a56a
- PR #2750 (PM ledger sync, gate-ID rename) — commit 888e0b1
- PR #2745 (cool-carp-720 WI-2 impl) — rename applied
This PR completes the cascade by renaming the main-state content.

Rationale stack per feedback_pre_compaction_framings_self_supersede:
operator BLOCKING identifying a verifiable INVARIANTS violation
supersedes prior ratification at the violating element only. Director
msg_4f7f536d ratification at sum-type-name level is superseded;
variant names + 23-site migration scope + 🟡 YELLOW classification +
projection function signature + gunbc-namespace placement +
dissolution trigger all stand.

If Director adjudicates ALTERNATE (rename SELF_HOSTING.md:609 instead),
this PR + the 4 in-flight rename commits revert as a unit.

Mechanical rename: 26 occurrences (EmissionTarget → WorkflowRuntime +
emission_target → workflow_runtime). Status header addendum documents
the rename + cross-links PR #2749 §7.3.3 + SELF_HOSTING.md:609.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: expand cascade rename — 4 more files in main (Director-affirmed)

Director affirmed option (1) cascade-rename per zesty-bear-812
msg_5dd7d82d. PM grep surfaced 5 additional files in origin/main with
EmissionTarget/emission_target references; Substrate Mgr triage:

GUNBC-NAMESPACE (rename):
- docs/design-ci-workflow-substrate-shape-2026-05-12.md (68 occurrences)
  — my own PR #2749 canvas that merged with pre-rename version before
  commit 575eb7e made it into the squash-merge
- docs/briefs/r3-t-wad-full-r3-emission-target-gunbc-ci-sketch.md (8)
  — explicit "gunbc CI projection mode" per file content; filename
  also renamed to r3-t-wad-full-r3-workflow-runtime-gunbc-ci-sketch.md
- docs/briefs/r3-t-wad-full-r3-slice-4-shape-agnostic-skeleton.md (3)
  — "EmissionTarget standalone gunbc sum type" per file content
- docs/design-section-1-8-acceptance-aggregator-pattern.md (2)
  — explicitly "substrate-shape (gunbc-namespace per (c-refined))"
  for emission_target_open_enum_landed gate

SHAPE-A (keep — not renamed):
- docs/briefs/r3-v-execute-command-foralltargets-collapse-audit.md (6)
  — PerEmissionTarget in ExecutionScope context; refers to Shape-A
  per-target compilation semantics ("L5 / target-spec owns
  per-emission-target compilation"); canonical SELF_HOSTING.md:609
  authority context, not the gunbc CI realization-mode collision

Total rename scope now: 5 files (originally 1).
Mechanical renames: 26 + 68 + 8 + 3 + 2 = 107 occurrences total.
Plus filename rename (1 file): emission-target → workflow-runtime in path.

Cascade structurally complete in this PR. PR body will be updated to
reflect expanded scope.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: fix rename artifacts in emitter-dispatch canvas (claude review 10107)

claude APPROVE_WITH_COMMENTS review 10107 on PR #2756 flagged three
rename artifacts:

1. workflow_workflow_runtime_toggle_proven at :575 — doubled name from
   sed re-applying to workflow_emission_target_* (sed pattern matched
   "emission_target" and "workflow" prefix concatenated). Fixed by
   running sed 's/workflow_workflow_runtime_/workflow_runtime_/g'.
   Result: workflow_runtime_toggle_proven.

2. workflow_workflow_runtime_consumed at :685 — same doubling pattern.
   Same fix; result: workflow_runtime_consumed.

3. §1 Non-Goals at :51 listed "introduce a new MatrixSpec, WorkflowRuntime,
   or sibling workflow carrier" — newly self-contradictory after rename
   since the canvas's primary type IS WorkflowRuntime. Reworded to
   "introduce a new MatrixSpec or sibling workflow carrier alongside the
   ratified WorkflowRuntime" with explicit note that WorkflowRuntime
   itself is in scope.

All three are pure rename artifacts; no substrate-shape changes.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: fix doubled workflow_workflow_runtime in substrate-shape canvas

cursor APPROVE_WITH_COMMENTS review 10112 on PR #2756 caught the same
sed-doubling pattern in docs/design-ci-workflow-substrate-shape-2026-05-12.md
at :401, :430, :436, :441, :521 — workflow_workflow_runtime_toggle_proven
should be workflow_runtime_toggle_proven (matching the sibling
emitter-dispatch canvas).

Prior commit 8344a8b fixed the same pattern in emitter-dispatch.md
but missed this file. Now both canvases use the single identifier
workflow_runtime_toggle_proven — restoring "one checkable name for one
fact" per INVARIANTS.md P2 at the documentation/program-tracking layer.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: add §7.3.3 rename record + restore Shape-A EmissionTarget citation

codex review on PR #2756 sha 8708df7 (non-blocking) caught two
citation gaps after the cascade rename:

1. emitter-dispatch.md status note cites PR #2749 §7.3.3, but the
   merged-on-main substrate-shape canvas had only §7.3.1/§7.3.2
   (the §7.3.3 rename-record I authored on the unmerged PR #2749
   branch did not make it into the squash-merge).
2. r3-t-wad-full-r3-workflow-runtime-gunbc-ci-sketch.md mass-renamed
   "EmissionTarget" → "WorkflowRuntime" including the SELF_HOSTING.md
   citation that should have preserved the Shape-A name to distinguish
   it from the renamed T-CI-WAD WorkflowRuntime.

Fixes:

(1) Added §7.3.3 to docs/design-ci-workflow-substrate-shape-2026-05-12.md
documenting the rename + SELF_HOSTING.md:609 authority + Director
re-ratification per msg_5dd7d82d. Now emitter-dispatch.md's §7.3.3
citation resolves to actual content in main post-merge.

(2) Restored Shape-A "EmissionTarget" name in the SELF_HOSTING.md
citation in r3-t-wad-full-r3-workflow-runtime-gunbc-ci-sketch.md:13.
Expanded the citation to include the full SELF_HOSTING.md:609 type
declaration so the distinction between Shape-A EmissionTarget (compiler
language targets) and renamed T-CI-WAD WorkflowRuntime (gunbc CI
projection mode) is unambiguous at the brief level.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): rewrite line 850 to remove '+ cascade' diff-marker artifact — codex review 741f102

Prose now reads as a cascade list rather than a stray diff '+' line.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
…y worker brief (#2762)

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: canvas RATIFIED — §7 ratification dispositions

Director (zesty-bear-812) ratified option (c) at 2026-05-12T07:39:44Z
per PR #2751 comment (session msg_168005e1 to PM deep-wolf-155).

- Status header updated to RATIFIED
- §7 added with 4 ratification points + cascade implications:
  1. Expression sum-type at dsl/extdeps/github/actions.dag: RATIFIED
  2. Single OpaqueString variant + 🟡 YELLOW: RATIFIED
  3. Three-condition dissolution trigger: RATIFIED
  4. 5-site uniform migration: RATIFIED
- Cascade documented: cool-carp-720 (WI-2) Expression wrapping;
  stern-stag-854 (Slice 4-5) emit logic stays trivial; PR #2746 can
  reference ratified Expression substrate

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: site-count correction — 5→7 expression sites in actions.dag

Operator BLOCKING inline review on PR #2751 at :34 (briansrls
2026-05-12T07:45:24Z) flagged that actions.dag has Job.if_condition
+ RunStep.if_condition + UsesStep.if_condition (3 if_condition sites),
not 1. Same expansion applies to env: RunStep.env + UsesStep.env (2
sites), not 1.

Finding accepted. Actual migration scope is 7 sites total:
- Job.if_condition (:117)
- RunStep.if_condition (:154)
- UsesStep.if_condition (:163)
- RunnerSpec (new ExpressionRunner variant)
- ConcurrencySpec.group (:?)
- Step.with[k] (UsesStep:160)
- RunStep.env (:151) + UsesStep.env (:162)

Updates:
- §1 table: if_condition row shows 3 sites; env row shows 2 sites
- §1 narrative: "seven expression sites" with enumeration
- §2 (a/b/c) code samples: all 7 sites in option (c) sketch; Step
  carrier modeled with RunStep/UsesStep variants properly
- §3 reasoning point #1: explicit P2/P5 framing — leaving any
  if_condition/env site un-migrated creates hidden parallel authority
  (typed at one site, opaque at others) blocking P5 dissolution at
  un-migrated sites
- §5 / §6 / §7 site-count refs updated
- §7 site-count correction note: framing the expansion as
  site-count correction, NOT substrate-shape correction — ratification
  point #4's "single-authority for expression substrate" already covered
  ALL expression sites in actions.dag uniformly; 7-site scope is
  implementing-PR responsibility

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §4 dissolution target — template-string layer for extdeps fidelity

Operator BLOCKING #2 on PR #2751 at :214 (briansrls 2026-05-12T07:45:24Z):
the §4 dissolution target sketched a pure Expression AST, but GH Actions
expression-bearing scalars are template strings with alternating literal-
text and ${{...}} segments (e.g., concurrency.group:
${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }}).
A pure-AST terminal shape under-models what the platform actually parses,
violating INVARIANTS.md P1 (modeling faithfulness).

Finding accepted. §4 dissolution target corrected to two-layer shape:

  Expression
    = OpaqueString(String)
    | Template(List<TemplateSegment>)

  TemplateSegment
    = TextSegment(String)
    | ExpressionSegment(ExpressionAst)

  ExpressionAst = Literal | Var | BinOp | Func | Index (etc.)

This is extdeps-faithful: mirrors the platform's actual parse structure
(template-string layer over expression-AST layer). Pure-literal /
pure-expression / mixed scalars all collapse cleanly into the segment
list.

Original sketch preserved as authoring-evolution record; corrected shape
supersedes.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §6 Q#1 RESOLVED — sum form, not record (per BLOCKING at :258)

Operator BLOCKING #3 on PR #2751 at :258 (briansrls 2026-05-12T07:45:24Z):
§6 open question #1 incorrectly treated record form and one-arm sum as
equivalent. A record form (type Expression { value: String }) does NOT
preserve:
- Single-arm pattern-match property on consumers (record access
  projects to .value as String; no tag to match)
- Single-edit second-variant dissolution path (record → sum is a
  carrier-shape change, not a one-line declaration edit; every
  consumer must be rewritten to switch from .value access to
  pattern-match)

This breaks Practice 4 (coproduct dissolution) and P5 (Progress Is
Dissolution) — the dissolution receipt the YELLOW classification
relies on assumes the dissolution is cheap; record form makes it
expensive.

Q#1 resolved inline: Expression lands as a one-arm sum
(type Expression = OpaqueString(String)), NOT a record. This was
implied by §3 reasoning point #4 ("Pre-empts the type-alias trap")
which applies equally to record-form aliases, but the §6 framing
treated both as admissible — corrected.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: add CI workflow emitter-dispatch canvas (#2746)

* docs: add CI workflow emitter-dispatch canvas

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* docs: align workflow emitter canvas with substrate comparison

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* docs: keep InlineGunbc out of initial target enum

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* docs(r3): §1.8 acceptance-aggregator pattern scaffold (pilot) (#2748)

* docs(r3): expand R3 lanes to 12 + lens-framework invariant + analysis findings

User directive 2026-04-30: "nothing can be deferred past R3 - we have to
readjust R3 if something is missing." PM-driven audit + Director ratification.

R3 lane expansion (10 → 12):
- T-V2-Retirement (NEW; PB Manager continuation): src/v2/ retirement
  cascades from T-FixedPoint + T-LensProducer-Retirement; structurally
  cheap to pull in. Gates: v2_oracle_no_remaining_test_consumers +
  v2_directory_deleted.
- T-Free-Consequences-Demonstration (NEW; Verification Manager): 10-gate
  TestClaim suite operationalizing thesis "free consequences" framing.
  Auto-parallelism + auto-memoization + cross-target opt + space-bound CX.
  Loop-iteration parallelism: sequential default + opt-in via
  Lens<Iteration-Independence> (zero-heuristic; same shape as
  Lens<Bind-Independence>).

Priority corrections folded into existing lanes (no new lanes):
- C1 (T-Tier3-Dissolution sub-gate): tier3_mirror_dissolution_perf_within_budget
  with thresholds <=2x median, <=5x p99 (cargo bench fixtures per retired
  mirror).
- C2 (Substrate continuation, T-Anthropic-Wire scope expansion):
  ProviderTypedWire<P> carrier extracted IN R3 (path (a) commit; drops the
  prior 6-month elapsed-time check exactly per user directive).

design-lens-framework.md amendment:
- Lens.read MUST depend only on (Node, Behavior) pair, not external state.
- Locks memoizable shape; runtime memoization becomes auto-memoization free
  consequence instance (T-Free-Consequences-Demonstration).

ROADMAP.md additions (### Post-merge debt (2026-04-30 analyses)):
- 4 novel findings from paired exploratory + reflective analyses
  (gpt-5-5-pro 991114f / gpt-5-5-thinking ad016c5):
  * Duplicate record-literal fields silently dropped (highest-value bug)
  * ValueBody Rust<->.dag mirror drift; no isomorphism gate
  * FieldMap duplicate-free invariant lost in .dag mirror
  * Operator inference fabricates (T,T)->T for non-algebra LHS
- 8 reflective-analysis priority corrections folded into R3 trajectory
- 2 stale rows marked RESOLVED (repeat_string + lower_fn_body re-derive)

Routed to R3 Mgrs via inbox dispatches (#1130 / #1131 / #1133 / #1276 / #846).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): reframe Rust<->.dag isomorphism as producer-first

cool-crab-614 PR #1324 research reframed the proposal: missing substrate
is a reflected-Dag query/report PRODUCER (Lens<DagShapeReport>), not a
new predicate variant. RustDagIsomorphism becomes a CONSUMER (TestClaim
comparing two DagShapeReport outputs via BinaryDimensionReportEquals),
eliminating parallel-authority risk.

Reflection-aware modifiers for unified BinaryDimensionReportEquals now
cover 4 surfaces: TC1 eta-equivalence + TC2 strategy-order + TC3
evaluation-step + shape-report (reflected-Dag query).

Single substrate-introduction; multiple consumers via reflection-aware
modifiers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): fix lower_fn_body row citation per #1319 review

PR #1319 review (cursor 9d2dffb) flagged that the RESOLVED note cited
`src/v3/compiler/src/lower.rs:61670-61688` but lower.rs is only 7919
lines. Original line citations referenced the analysis snapshot's
aggregate-numbering scheme, not live file.

Verified live state: `lower_fn_body_into_existing_decl` symbol does NOT
exist in current lower.rs; equivalent path is `lower_fn_item_expr_body`
(:4410+); non-Arrow arm at :4433-4451 reports
`Diagnostic::ResolveError` with explicit invariant-violation message
("violated lowering invariant: seed_function_signatures_phase did not
produce an Arrow connective for this Fn") and returns outer_scope.
That IS the fail-closed shape the original row asked for; resolution
note now correctly cites live behavior.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): resolve v2-retirement contradiction per #1319 review

PR #1319 review (codex a9a9894) flagged contradiction: T-V2-Retirement
added as R3 lane (line 100) but Compromises table (line 165) still
listed v2 retirement as Post-R3 operational cleanup. INVARIANTS P1
"Documentation Describes Live State" violation.

Fix: strikethrough the post-R3 entry; explicitly note migration into
R3 as T-V2-Retirement lane per 2026-04-30 user directive "nothing can
be deferred past R3." Single authoritative placement; cross-link to
Lane structure §11.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* docs(r3): aggregator pattern — coercion table + precondition + exclusion rules

Addresses BLOCKING #2748 (briansrls inline at L71): live §1.8 uses 7 status
values, not 3 (PASSING, SATISFIED-BY-CONSTRUCTION, CONSUMER_LANDED, DECLARED,
R3-LOAD-BEARING, HELD-CANVAS-DEFERRED, DEFERRED). The 3-value lattice meet
was not machine-checkable as written.

- Coercion table: SATISFIED-BY-CONSTRUCTION → PASSING; INTEGRATION_RECEIPT
  partial-slice → CONSUMER_LANDED; identity for the 3 lattice values.
- Precondition rule: bare R3-LOAD-BEARING is scope-metadata, not closure
  progress; constituents with that status are not aggregator-ready until
  cell inlines closure-progress (e.g., 'R3-LOAD-BEARING — DECLARED').
- Exclusion rule: DEFERRED + HELD-CANVAS-DEFERRED MUST NOT appear in any
  aggregator's depends_on: per §1.5 honest-close arithmetic.
- Cluster F candidate reframed: NOT aggregator-ready at HEAD because rows
  #81/#82/#83/#95 carry bare R3-LOAD-BEARING; precondition fix required
  before pilot. Cluster M / K / V2-Retirement candidates similarly subject
  to precondition check at pilot time.
- Invariants P2 cleanliness note: coercion table + precondition + exclusion
  are themselves a single derivation authority; no parallel authority for
  closure progress.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): cascade ci_yml_deleted → ci_yml_hand_authority_dissolved rename

Per PM cascade (PR #2744 commit 19a1d8d absorbing briansrls BLOCKING
on line 32): file artifact presence is orthogonal to hand-authority
dissolution. YamlStatic / BinaryShim / PythonShim all require some
.github/workflows/ci.yml for GH Actions trigger discovery; P5 / Pure
Bootstrap dissolves authority, not file presence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): relocate aggregator pattern from §1.8 to §1.9 per codex P2 finding

Addresses codex REQUEST_CHANGES /api/reviews/9982 on PR #2748: putting
aggregator rows directly in §1.8 alongside their constituents violated
INVARIANTS P2 single-authority — even with "derived not hand-set" prose,
the row shape didn't structurally prevent treatment as a closure
obligation, and the side-taxonomy of "does not participate in §1.7
corpus rules" was a P2 boundary-discipline violation inside the
canonical ledger.

Restructured:
- Aggregators relocated to a NEW §1.9 section (separate table)
- Distinct ID namespace: V1, V2, ... (NOT numeric §1.8 row IDs)
- Different table columns (View ID / View Name / Cluster Lane /
  depends_on: / Derived Status / Notes) to make visual distinction
  obvious
- depends_on: references §1.8 row #s by foreign-key style
- Derived Status rendered as <DERIVED> in committed text; never stored
  as snapshot (per feedback_no_snapshot_integers_in_briefs)
- §1.8 "97 enumerated / 96 R3-load-bearing" arithmetic preserved
  unchanged; §1.9 entries do not appear in that arithmetic
- Coercion table + precondition + exclusion rules carried forward
- Cluster F precondition catch (rows #81/#82/#83/#95 carry bare
  R3-LOAD-BEARING) preserved

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): annotate R4-carve citation with supersession marker

Fixes CI failure on PR #2748: scripts/check-r4-carve-dissolution-discipline.sh
flagged the coercion-table row for R3-LOAD-BEARING which mentioned 'R4-carved'
without a supersession annotation. Reframed to cite carve-promotion-IN-R3
2026-05-09 + DISSOLVED status per Director ratification gunbc#846.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): correct #83 characterization + add filename note

Per cursor APPROVE_WITH_COMMENTS /api/reviews/10000 on PR #2748:

- Row #83 (lens_capability_register_zero_proxy_zero_stub) was incorrectly
  listed alongside #81/#82/#95 as carrying "bare R3-LOAD-BEARING". The
  authoritative ledger has #83 reading "DECLARED — full scope IN R3
  (carve-promotion-IN-R3 2026-05-09)", which inlines closure-progress
  alongside scope-metadata and already coerces to DECLARED under the
  precondition rule. Reframed #83 as a positive counter-example showing
  the inline-pattern #81/#82/#95 still need to adopt.

- Added top-of-doc filename note explaining the §1.8 vs §1.9 mismatch:
  filename retained for review-thread anchor stability; substantive
  section is §1.9.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add sunset condition for aggregator pattern pilot doc

Per cursor /api/reviews/10013 optional tighten: PILOT scaffold needs a
single checkable sunset to satisfy P5 scaffold-posture discipline.
Sunset: doc retires when docs/r3-program-plan.md contains §1.9 per the
specified table shape AND at least one §1.9 view entry is live in the
ledger.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add composite-status coercion rule (CONSUMER_LANDED + PASSING)

Addresses briansrls BLOCKING inline at L66 on PR #2748: coercion table
omitted live §1.8 composite forms like 'CONSUMER_LANDED + PASSING'
(~25 instances in the ledger, including candidate Cluster M constituent
#86 program_generator_carrier_landed).

Added:
- Explicit row for 'CONSUMER_LANDED + PASSING' → PASSING
- General composite rule '<earlier> + <later>' → coerce to <later>
  (rightmost component; conjunction-of-progression-stages semantics);
  covers future composite forms not enumerated.

This makes #86 view-ready under the precondition rule (coerces cleanly
to PASSING).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag) (#2747)

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* docs: add CI workflow emitter-dispatch canvas

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* docs: add T-CI-WAD slice 4 skeleton

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* docs: clarify T-CI-WAD projection sketch

* docs: align T-CI-WAD prep with c-refined shape

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* docs(r3): T-WAD substrate-shape comparison canvas — gate #56 (#2749)

* docs(r3): flip §1.8 #85 forall_exists_quantifier_substrate_landed to CONSUMER_LANDED + PASSING

PR #2647 (vivid-dove-106 / Cluster M Phase 1a) merged carriers into src/v3/std/verification.dag at HEAD; ledger row was drifted DECLARED. Per post-merge ledger-receipt sync discipline (Director-ratified at gunbc#828 c#4415884211).

Caught by Debt-Paydown PM ledger-sync check — thanks silent-ram-834.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): downgrade §1.8 #85 to DECLARED per codex BLOCKING + row #17 precedent

Prior CONSUMER_LANDED + PASSING flip overstated the gate per INVARIANTS §P2 strict reading: carriers + hand-written ratchet ≠ generated consumer proof. Mirrors row #17 (numeric_abstract_carriers_landed) shape: carrier substrate landed, hand-written ratchet noted, CONSUMER_LANDED deferred to generated consumer + SuiteClaim wrapper migration + V Mgr #87 runner consumer.

Sibling row #86 carries same overclaim risk via PR #2645 precedent — separate amendment if Director rules.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: T-WAD substrate-shape comparison canvas (gate #56)

Mgr-tier comparison canvas surfacing three substrate-shape options for
gate #56 ci_workflow_modeled_as_dag under FULL R3-close elevation:

- (a) PR #2736 provider-neutral CIWorkflowDag (semantic-only)
- (b) WI-1 PR #2746 actions.dag-concrete + EmissionTarget? (transport-only)
- (c) Hybrid — CIWorkflowDag as semantic source + Workflow.emission_target
  as transport-artifact selector + projection function project_github_actions:
  CIWorkflowDag -> Workflow as the structural fold connecting them

§0 grep-verifies PR #2736 body claim ("hand-authored GitHub Actions transport
copy was removed") against actual diff: actions.dag Workflow/Job/Step
carriers at :21/:110/:147 intact; PR adds CIWorkflowDag without removing
actions.dag carriers, leaving dual-authority unresolved at HEAD.

§5 recommends option (c) for Director ratification on:
- single-authority per concept layer (gate-dependency at gunbc.ci;
  transport at extdeps.github.actions) per MODELING.md M9
- decoupled cost-of-change axes (new provider vs new emission target)
- preserves both already-authored PRs' substrate contributions
- aligns with docs/design-emission-model.md single-emitter discipline

Authority: PM relay msg_a945b141 (deep-wolf-155) routing Director
msg_34e9a381 substrate-shape question per
feedback_substrate_shape_belongs_in_mgr_canvas.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7 addendum — INVARIANTS P1 reframes (c) to (c-refined)

BLOCKING inline review on PR #2746 (briansrls c#4427988541) flagged
that adding EmissionTarget to dsl/extdeps/github/actions.dag puts a
gunbc emission-policy fact into the GitHub Actions platform model,
violating extdeps fidelity and INVARIANTS P1.

§7 accepts the finding (structurally correct per actions.dag header
:1-12 platform-vs-CI-logic discriminator), disqualifies §1 option (b)
as-authored, partially invalidates §1 option (c) as-authored (the
two-layer concept-layering argument STILL holds; only the EmissionTarget
placement on extdeps fails P1).

§7.3 surfaces option (c-refined): EmissionTarget lives in gunbc/ci.dag
as a sum type + parameter to project_github_actions(ci_workflow_dag,
target) -> Workflow. extdeps.github.actions.Workflow is unmodified.
Pinned Workflow values for emission validation live in gunbc namespace.

§7.5 revises ratification asks: PR #2746 disposition shifts from
"framing-narrowing" to substantive substrate retraction on the field-
placement decision (sum-type shape stands; placement relocates).

§7.6 distinguishes (c-refined) from PM-proposed alternatives:
- not PM(b) [EmissionTarget on CIPipeline] — same M9 join-cost as
  PR #2746 §3 Option B
- not PM(c) [WorkflowEmission wrapper] — same sibling-decision cost
  PR #2746 §3 Option C already rejected
(c-refined) expresses emission-target choice at the projection
invocation (per docs/design-emission-model.md: emission is structural
projection, choice is property of the call not the value).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §8 retraction — derive Workflow from projection, not separate authority

codex REQUEST_CHANGES on PR #2749 (review 9970) flagged that option (c)
as authored proposed both a projection function CIWorkflowDag -> Workflow
AND a separately hand-declared Workflow value the emitter "validates
against" as a pinned target — INVARIANTS P2 / modeling-discipline.md
Practice 5 dual-authority condition.

Finding accepted. §8 retracts the pinned-Workflow-as-modeled-authority
framing; in-place edits applied to §1 (option (c) intro), §4 (S0
sequencing), §5 (ratification ask #5), §7.3 (WI-2 placement), §7.5
(revised recommendation).

Replacement framing: the only Workflow value in modeled authority is
the projection function output, structurally derived from a single
source. WI-2's gunbc_ci_yml_workflow becomes a name binding to the
derived result (data gunbc_ci_yml_workflow: Workflow =
project_github_actions(ci_workflow_dag, YamlStatic)), not an
independent declaration. Byte-level regression fixtures live in
tests/, not dsl/, and are not part of modeled authority.

Layering argument unchanged: gate-dependency at gunbc.ci.CIWorkflowDag;
platform transport at extdeps.github.actions.Workflow (unmodified);
emission policy in gunbc namespace; artifact derived from single source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: cite feedback_extdeps_header_discriminator_before_field_placement

Per PM relay msg_72e2ab50: Director memorialized actions.dag:1-12
discriminator rule as feedback_extdeps_header_discriminator_before_field_placement.
Add citation in §7's discriminator block for audit trail.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: cite P2 (Boundary Discipline) not P1 for single-authority

gpt-5.5-pro APPROVE_WITH_COMMENTS review 9972 caught that the
single-authority / "every fact lives in exactly one place" principle
is INVARIANTS.md P2 Boundary Discipline, not P1. P1 is Modeling
Faithfulness.

Operator BLOCKING quote at §7 invoked "P1" verbatim; both principles
are in play:
- P2 because emission-policy authority must live in exactly one place
  (gunbc/ci.dag), not split across extdeps and gunbc
- P1 because placing gunbc-policy state on an extdeps carrier makes
  the carrier no longer faithful to its header's "platform facts
  only" claim

§7.1 prose updated to explicitly distinguish the two principles and
note that subsequent single-authority references cite P2.
§7.4 table row relabeled "INVARIANTS P2 (Boundary Discipline / single
authority)".
§7.5 ratification ask #2 cites P2 + P1.
§7 heading updated to "INVARIANTS P2/P1 BLOCKING reframes (c)".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: classify EmissionTarget coproduct per Practice 4 (§7.3.1)

BLOCKING inline review on PR #2749 at line :573 (briansrls
2026-05-12T07:04:15Z): proposed EmissionTarget 4-variant coproduct
landed without 🟢/🟡/🔴 dissolution classification, violating
modeling-discipline.md Practice 4 (coproduct dissolution).

Finding accepted. §7.3.1 added classifying EmissionTarget as
🟡 YELLOW (scaffold) with full reasoning across all four dissolution
patterns:
- Pattern 1 (fact placement): N/A — empty payloads
- Pattern 2 (variant-is-data): blocked by closed-set guardrail
- Pattern 3 (algebraic form): N/A — not std/ algebraic operations
- Pattern 4 (dimensional): live dissolution path; ~2-3 axes
  (target_language, requires_shim, runtime_executes) plausible but
  not yet forced at four variants

YELLOW not GREEN: Pattern 4 plausibly works; closing the door would
be wrong. YELLOW not RED: dissolving prematurely without consumer-
side pressure risks landing wrong axes (requires_shim partially
redundant with target_language at current variants).

Named dissolution trigger (per YELLOW requirements): (a) fifth
target landing that breaks the four-way axis, OR (b) consumer needing
single-dimension pattern-match, OR (c) Slice 4/5 implementation
surfacing an unpredicted axis. Any forces dimensional record shape.

Ledger note: classification is canvas-level; implementing PR (WI-2
re-brief per §5/§7.5 ask #4) MUST carry the same classification +
trigger as a // 🟡 YELLOW (scaffold) comment on the type declaration
citing this canvas §7.3.1.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: canvas RATIFIED — §9 ratification dispositions

Director (zesty-bear-812) ratified option (c-refined) at
2026-05-12T07:04:18Z per PR #2749 comment (session msg_4f7f536d
to PM deep-wolf-155). Updates:

- Status header changed to RATIFIED with ratification authority
  citation
- §9 added with all 5 ratification asks dispositioned:
  - (c-refined) substrate-shape: RATIFIED
  - PR #2746: AMEND (4 specific changes for still-heron-763)
  - PR #2736 body: SATISFIED prior
  - PR #2745 WI-2: SCOPE EXPANSION APPROVED, PM authors re-brief
  - S1 projection function: NEW §1.8 GATE (project_github_actions_landed,
    substrate-shape family); aggregator pilot row #56+4→#56+5
- Downstream cascade documented per Director directive

Director attributed feedback_extdeps_header_discriminator_before_field_placement
discipline rule to the §7+§8 self-correction trajectory.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: inline SUPERSEDED banners on §1(c)/§2.3/§3/§4/§5

codex BLOCKING review 9986 at sha 38c28cd flagged that §2.3/§3/§5
still contain the now-overturned option-(c)-as-authored framing
(EmissionTarget on extdeps.Workflow + hand-declared pinned Workflow).
For a RATIFIED canvas, leaving those sections unmarked materially
states the wrong substrate shape — readers would have to read through
to §7/§8/§9 to discover the supersession.

Finding accepted. Inline SUPERSEDED banners added at the top of:
- §1 Option (c) sub-section: points to §7.3/§7.4/§8/§9 for current shape
- §2.3 Option (c) evaluation: flags the "emission validates declared
  Workflow against projection" sentence as the dual-authority condition
  §8 retracts
- §3 WI-1 assumption-breakage: OVERTURNED bullets explicitly listed
  (placement, "Workflow chooses target" framing, framing-narrowing
  disposition)
- §4 Slice sequencing under (c): SUPERSEDED in part — structure
  remains valid under (c-refined); placement-specific descriptions
  overturned by §7/§8; WI-2 scope larger than §5.4 implied per §9 ask #4
- §5 Recommendation: all three positions (extdeps placement,
  framing-narrowing PR #2746 disposition, pinned-Workflow validation
  target) OVERTURNED; current recommendation is (c-refined) per §7.5+§9

Earlier framings preserved as canvas-evolution record (showing
self-correction trajectory through §7+§8), but each affected section
now flags its own superseded status without requiring a full-doc read.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §6 Q#2 RESOLVED banner — overturned superseded Workflow framing

cursor APPROVE_WITH_COMMENTS review 10001 (non-blocking) noted that §6
open question #2 still partly explained the projected signature via
"PR #2746 places the field on Workflow", which contradicts §7.3
(c-refined) where extdeps.github.actions.Workflow is frozen unmodified.

Fix: add inline RESOLVED banner at §6 head pointing to §7.3 + §9; rewrite
Q#2 entry to flag the superseded framing inline — the parametric
signature was the right answer regardless of placement, but the rationale
over-attributed to a placement that no longer stands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: inline 🟡 YELLOW checkpoint at §7.3 EmissionTarget declaration

Operator BLOCKING inline review on PR #2749 at :657 (briansrls
2026-05-12T07:58:34Z): the §7.3 code block declaring type
EmissionTarget lacked the inline 🟢/🟡/🔴 classification annotation
required by modeling-discipline.md Practice 4 "any new enum with
N ≥ 2 variants must have a checkpoint comment naming its classification."

The classification reasoning exists in §7.3.1 prose section, but the
declaration site itself was missing the checkpoint comment, which is
the form Practice 4 requires.

Fix: add inline 🟡 YELLOW (scaffold) comment block above the type
declaration citing §7.3.1 for full reasoning + the three-condition
dissolution trigger + likely Pattern 4 dissolution path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7.3.2 Shape A/B clarification — EmissionTarget names realization modes

Operator BLOCKING inline review on PR #2749 at :657 (briansrls
2026-05-12T07:58:35Z): YamlStatic variant of EmissionTarget would
"make a Shape B CI YAML artifact mode an emission target despite
THESIS Shape A/B requiring YAML artifacts to be generated by .dag
user programs, not compiler emission targets."

Per THESIS:215-216, Shape A = compiler language targets (compiler
emits directly); Shape B = user-program artifacts (YAML, Terraform,
K8s, etc. — emitted by .dag programs walking typed values, NOT
compiler render targets). YAML for ci.yml is Shape B; gunbc
doesn't have a YAML emission target.

Finding accepted as naming-and-framing concern, not substrate-shape
concern. Added §7.3.2 clarifying:

- EmissionTarget names a REALIZATION MODE selector, not a parallel
  compiler emission target
- YamlStatic = Shape B (.dag program renders YAML from Workflow)
- BinaryShim = Shape A binary + Shape B YAML shim wrapper
- PythonShim = Shape A Python + Shape B YAML shim wrapper
- InlineGunbc = Shape A (gunbc runtime as host)

No substrate retraction: variants, YELLOW classification, dissolution
trigger, gunbc-namespace placement, parametric signature all stand.
Naming consideration noted (WorkflowRealizationMode would carry less
Shape-A baggage), but renaming forces re-ratification without
corresponding substrate change — keep name, document the mapping at
declaration site per §7.5 ask #4 implementation PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: fix §9 ask #5 slice/gate name — Slice 8 ci_yml_dissolved, not Slice 5 ci_yml_deleted

gpt-5.5-pro REQUEST_CHANGES on PR #2749 sha f5b57e7 (review 10037)
caught that §9 ratification ask #5 wrote the projection-function gate
as "discrete from Slice 5 (ci_yml_deleted, state-check)", but per the
canvas's own §1 (Director-ratified gate-set) and §4 Slice sequencing:
- Slice 5 = BinaryShim emitter (workflow_emission_target_toggle_proven)
- Slice 8 = ci.yml dissolution (gate name: ci_yml_dissolved)

The conflation could mislead workers updating PR #2748 to wire the new
project_github_actions_landed gate against the wrong slice/gate.

Fix: §9 ask #5 now reads "discrete from Slice 8 ci_yml_dissolved",
matching the canvas's earlier authoritative gate-set + §4 sequencing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: §5.5 inventory audit — 7→22 expression-capable fields

codex BLOCKING (review on sha 4f41aeb) + operator BLOCKING inline at
:315 (2026-05-12 ~09:12Z): site inventory was keyed to ci.yml examples
not actions.dag schema + GH Actions context-availability docs.
Under-modeling the platform expression-capable surface by ~15 sites.

Finding accepted as substantive scope correction. Added §5.5 with
full audit table against actions.dag HEAD + GH Actions docs:

Total expression-capable surface: 22 fields across Workflow / Job /
RunStep / UsesStep / ConcurrencySpec / RunnerSpec. The 7-site
enumeration was the ci.yml-keyed minimum subset; the
actions.dag-keyed audit extends to 22.

§5.5.1 sets migration rule: ALL expression-capable fields migrate
uniformly under (c). Per-field opt-in produces hidden parallel
authority (P2/P5 violation). Implementing PR audits against actions.dag
HEAD + GH Actions context-availability docs and migrates any
additional sites surfaced.

§5.5.2 surfaces typed-field expression semantics as new substantive
question (§6 Q#4) — timeout_minutes/continue_on_error/cancel_in_progress
are typed fields where GH Actions string-coerces expressions. Three
candidate shapes (wrap / TypedOrExpression sum / defer); Director-tier
choice.

§5.5.3 retains §1/§2 7-site framing as ci.yml-keyed reference;
substrate-shape ratification covers expanded 22-site scope per §5.5.1
migration rule.

§6 Q#2 sequencing updated to "22 expression-capable fields"; new Q#4
adds typed-field semantics question.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: update PR #2749 cross-link — EmissionTarget → WorkflowRuntime

Per PR #2749 commit 575eb7e (rename EmissionTarget → WorkflowRuntime
to resolve P2 name-collision with src/v3/SELF_HOSTING.md:609 Shape-A
EmissionTarget), update the single cross-reference in §7 here to match
the new name. Substantive content unchanged — orthogonal-axes argument
still holds.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §5.5.1 — split 22 sites into 13 string + 7 typed-field + 2 enum-ext

codex REQUEST_CHANGES on PR #2751 review 10083 (sha presumably 0cc2c28e
or 28d503c): §5.5.1 said "ALL 22 expression-capable fields migrate to
Expression" but §5.5.2 / §6 Q#4 left typed-field shape (Int?/Bool sites)
as an open Director-tier question. Implementer following §5.5.1 would
author the wrap-to-Expression shape immediately while §5.5.2 says hold.

Finding accepted. §5.5.1 split into three classes:

- 13 string-typed sites — uniform String→Expression migration, in scope
  for §7.5 ask #4 prereq PR
- 7 typed-field sites (timeout_minutes/continue_on_error/
  cancel_in_progress) — HOLD until §6 Q#4 ratifies wrap/sum/defer
- 2 enum-extension sites (RunnerSpec, UsesStep.uses) — new variant
  added to existing sum/struct, in scope for §7.5 ask #4 prereq PR

In-scope for substrate-prereq PR: 13 + 2 = 15 sites. Out-of-scope
(deferred): 7 typed-field sites.

§5.5.1 now non-contradictory with §5.5.2 / §6 Q#4: implementer reading
§5.5.1 migrates 15 sites; the 7 typed-field sites explicitly HOLD with
a named trigger (§6 Q#4 ratification).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §5.5 inventory expansion — add Workflow.name + Job.name (22→24 sites)

Operator BLOCKING on PR #2751 at :365 (briansrls 2026-05-12T10:12:15Z):
the string-typed migration class omitted Job.name: String?; GH Actions
context-availability table lists jobs.<job_id>.name as expression-capable.
Same applies to Workflow.name (workflow name supports expressions).

Audit gap fixed. §5.5 table adds:
- Workflow.name: String (:22) — string-typed expression-capable
- Job.name: String? (:112) — string-typed expression-capable

Counts updated:
- Total expression-capable: 22 → 24 sites
- String-typed class: 13 → 15 sites
- In-scope for prereq PR: 15 → 17 sites (15 string + 2 enum-extension)
- Out-of-scope (typed-field HOLD): 7 sites (unchanged)
- Under-modeling delta: 15 → 17 sites (ci.yml-keyed 7-site enumeration
  missed 17 sites in actions.dag schema)

§5.5.1 enumerated list of string-typed sites adds Workflow.name + Job.name.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: §5.5 — remove UsesStep.uses (literal-only per GH workflow-syntax)

Operator BLOCKING on PR #2751 at :381 (briansrls 2026-05-12T10:12:15Z):
classifying UsesStep.uses as expression-capable invents platform
capability — GH Actions workflow-syntax treats uses: as a literal
action location; the context-availability table does NOT list
jobs.<job_id>.steps.uses. Modeling it as expression-capable would
violate INVARIANTS.md P1 modeling faithfulness.

Verified against GH Actions docs (workflow-syntax + context-availability):
uses: is a literal action ref resolved before workflow expressions
evaluate.

Finding accepted. Removed UsesStep.uses from §5.5 inventory + struck out
the row + removed planned ExpressionActionRef variant from
enum-extension class.

Counts updated:
- Total: 24 → 23 sites
- Enum-extension class: 2 → 1 site (RunnerSpec only)
- In-scope for prereq PR: 17 → 16 sites (15 string + 1 enum-ext)
- Under-modeling delta: 17 → 16 sites
- Typed-field HOLD class: 7 sites (unchanged)

§5.5.1 enum-extension block now explains why UsesStep.uses was
removed for audit trail.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7 ratification ask #4 — reflect §5.5 expanded scope (16 in-scope, 7 HOLD)

Operator BLOCKING on PR #2751 at :543 (briansrls 2026-05-12T10:12:15Z):
§7 ratification dispositions still referenced the 7-site enumeration from
the original ratification framing, while §5.5 expanded the audit to
23 sites. Downstream implementation reading only §7 would preserve
opaque-string authorities at the non-§7-enumerated sites — P2/P5
violation by structural drift.

Fix: §7 ratification point #4 rewritten to cite §5.5 audit set + 16
in-scope sites + 7 typed-field HOLD class with named trigger.

Site-count correction note expanded from single-event to cumulative
correction sequence documenting all 4 BLOCKING-driven expansions
(5→7→22→24→23). Audit trail preserved; the (c) substrate-shape
ratification covers all 23 expression-capable sites uniformly per
"single-authority for expression substrate" principle — implementing
PR migrates 16 immediately, 7 typed-field sequenced post §6 Q#4
ratification.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 expand to MatrixStrategy carriers (23→28 sites; audit-methodology note per codex review 10128)

Cross-product of GH context-availability table × actions.dag carriers adds
MatrixStrategy.{dimensions,include,exclude,fail_fast,max_parallel}.
Updated counts: 28 total / 18 string-typed / 9 typed-field / 1 enum-ext;
19 in-scope for prereq PR, 9 HOLD for §6 Q#4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 remove Workflow.name (literal-only per GH context-availability; run-name is expression-capable key and not currently a Workflow field) — operator BLOCKING :274

28→27 total, 18→17 string-typed, 19→18 in-scope.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 add DispatchInput.default (operator BLOCKING :298) — workflow_call/workflow_dispatch input defaults per GH context-availability

27→28 total, 17→18 string-typed, 18→19 in-scope. MatrixStrategy already present per commit 9c1f0a1.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): status-block migration scope = 19 in-scope + 9 HOLD (was '5 sites uniform') — operator BLOCKING :7

Aligns top-of-file status with §5.5 / §7 ratified scope: 28 total / 18 string-typed + 1 enum-ext = 19 in-scope for prereq PR / 9 typed-field HOLD on §6 Q#4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5.1/§7/audit-trail count reconciliation (28/18/19/9) — cursor review 10134

Sweep stale internal counts: 23→28 site totals, 15→17 string-typed in audit blockquote, 5→9 typed-field, 16+7→19+9 deferred. Added correction step 5 to audit trail covering MatrixStrategy + DispatchInput.default additions and Workflow.name removal. Aligns §5.5.1, §5.5 audit-trail blockquote, §7.5 ask #4 with §5.5 audit totals.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): fix 'seven sites-already-migrated' (→19) + P5/modeling-discipline citation drift — cursor review 10145

:146 + :231-233: dissolution-cost wording updated from pre-§5.5 '7 sites' to post-audit '19 sites + 9 typed-field once §6 Q#4 resolves'.
:289-291: scaffold-arm sunset-milestone citation moved from INVARIANTS P5 (which mandates checkable dissolution trigger) to modeling-discipline.md Practice 4 (home of the scaffold-comment convention).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5.1 derivation discipline + add MatrixStrategy carriers to class lists; §6 Q#5 (DispatchInput carrier-split) + Q#6 (RunnerSpec runs-on grammar) — codex BLOCKING 10150

(1) §5.5.1 lists now explicitly enumerate MatrixStrategy carriers per class: dimensions/include/exclude in string-container (18 total), fail_fast/max_parallel in typed-field HOLD (9 total). Added explicit derivation-from-§5.5-table discipline note. Cross-check 18+9+1=28 ✓.

(2) §6 Q#5: shared DispatchInput collapses workflow_call vs workflow_dispatch expression-context-availability axes; carrier-split question surfaced (Director-tier sequencing relative to Slice 4 prereq PR).

(3) §6 Q#6: RunnerSpec under-models runs-on grammar (scalar/array/object + expressions at multiple positions); §2 (c) ExpressionRunner only covers scalar case. Carrier-split question surfaced.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(r3): DispatchInput.default → carrier-split-blocked class (workflow_dispatch is literal-only per GH context table) — operator BLOCKING :369

GH context-availability marks only on.workflow_call.inputs.<id>.default as expression-capable; on.workflow_dispatch.inputs.<id>.default is literal-only. Migrating the shared DispatchInput.default to Expression would invent workflow_dispatch capability (P1 violation).

§5.5 table row updated: ✗ split capability; §5.5.1 adds new 'carrier-split-blocked sites (1)' class; counts now 17 string-container + 9 typed-field-HOLD + 1 enum-extension + 1 carrier-split-blocked = 28 ✓. In-scope for prereq PR: 19→18. §6 Q#5 sharpened from 'sequencing question' to 'BLOCKED until carrier-split lands'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 Job.runner audit row + §5.5.1 enum-extension class flag partial-coverage (array/object/label-element expressions unmodeled) — operator BLOCKING :345

§2 (c) ExpressionRunner covers only whole-runs-on scalar-expression case. Array form (mixed literal/expression elements) and object form (group/labels expressions) require §6 Q#6 RunsOn carrier-split. Scalar-only case stays in §7.5 ask #4 prereq PR; array/object defer to §6 Q#6 resolution.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): tighten Slice 4 brief P2/P3 single-authority bar + carrier-gap STOP condition — codex BLOCKING review 10208

(1) Workflow field derivation: replace 'CIWorkflowDag content + structural defaults' with strict single-authority requirement; STOP authoring if any field lacks an input-domain source. No fabricated values, no second source of truth. P2/P3 bar made explicit per INVARIANTS + modeling-discipline Practices 3 + 5.

(2) Carrier-gap encounter: STOP condition for this PR (not side-channel-while-continuing). Worker must wait for warm-wolf-698 resolution (substrate-prereq PR / out-of-scope narrowing / brief revision) before resuming. Continuing with a gap = fabricated authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): correct PythonShim ratification — 3 initial arms (YamlStatic + BinaryShim + PythonShim) per emitter-dispatch canvas; only InlineGunbc is DESIGN-ONLY — operator BLOCKING PR #2768 :33

Earlier brief commit 4d40d3b erroneously demoted PythonShim to DESIGN-ONLY. Verified against origin/main:docs/design-ci-workflow-emitter-dispatch.md:126 — ratified shape is `WorkflowRuntime = YamlStatic | BinaryShim | PythonShim` with projection calls + acceptance semantics; only InlineGunbc is design-only pending real runtime consumer (canvas §5.4). Phase B updates Phase A enum + dissolution-trigger comment + Phase B BinaryShim+PythonShim stub note + reference list.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): replace RunStep.* / UsesStep.* glob with exact 17-site enumeration — operator BLOCKING PR #2768 :70

Glob shorthand was incorrectly broader than the §5.5.1 string-container set; would pull in UsesStep.uses (literal-only) + *.timeout_minutes/*.continue_on_error (typed HOLD). Now exact enumeration: Workflow.env (1) + Job.name/if_condition/env/concurrency.group (4) + RunStep.{name,run,env,working_directory,if_condition} (5) + UsesStep.{name,with,env,if_condition} (4) + MatrixStrategy.{dimensions,include,exclude} (3) = 17 ✓. Excluded fields explicitly noted.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
…ory cross-ref

Addresses claude #10308 review finding: §13's pointer to "previous draft in
git history at d534fd4" was a quirk for a brand-new file (per reviewer:
harmless but worth fixing). Inlines the PR #2745 misread walk-back trace
self-contained so readers don't need to git-log to follow the validation.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
…lans (#2775)

* docs: decomposition-algebra modeling project (DRAFT)

Operator-supplied premise: project decomposition as algebra where children sum to parent meaning; walk-back when integration contradicts construction.

This draft formalizes:
- §1 The contradiction trigger (algebraic imbalance | claim contradiction)
- §2 Types sketch (Node, Claim, Decomposition, Witness, WalkBackEvent) — gunbc-lens-style; eventual home in dsl/std/ as MeaningDecomposition lens analogous to Cost lens
- §3 Walk-back algorithm (procedure with StableAncestor | RootContested termination)
- §4 Worked example — PR #2745 misread retroactively traced through procedure (2026-05-12 PM execution error)
- §5 Dashboard comms application sketch — message-as-walk-back-signal mapping
- §6 Open questions (coefficient semantics, claim equivalence, root-asker, rebalance cost, implementation surface)
- §7 Next step: validate on N=3-5 real cases before .dag formalization

Iteration expected.

* docs: decomposition-algebra rewrite for ctrl/ migration scoping

Replaces procedural walk-back draft (d534fd4) with structural-integration
shape per operator directive 2026-05-12: migrate ctrl/ processes into .dag
substrate; algebra is authoritative, ctrl/ TS becomes projected emission.

Audit-grounded with grep-verified citations across dsl/std/ + ctrl PR refs
(#1192/#1193/#1195/#1197). Identifies 4 modeling gaps (EventLog<T> primitive,
Lens<A,B> type, bounded multiplicity, unified Witness) + workflow-types
dissolution scope (dsl/gunbc/workflow/types.dag overlaps with decomp-algebra;
proposed dissolution rather than coexistence). First-cut migration target
recommended: review-verdict-parser (today's parser-lag pain validates the
heuristic-pass cost per feedback_lenses_not_passes).

Phase 1 substrate-file skeleton (~50 lines) sketched. Cost-of-change
contract = 1 file for new Mode variants / Operation arms.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(decomp-algebra): inline §13 validation case study; drop git-history cross-ref

Addresses claude #10308 review finding: §13's pointer to "previous draft in
git history at d534fd4" was a quirk for a brand-new file (per reviewer:
harmless but worth fixing). Inlines the PR #2745 misread walk-back trace
self-contained so readers don't need to git-log to follow the validation.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: ctrl/ → .dag migration project plan (parallel program tree)

Companion to docs/design-decomposition-algebra.md. Authored per operator
directive 2026-05-12: parallel program tree beside zesty-bear-812, model
dependencies, migrate as much ctrl/ as possible ASAP.

Audit of ctrl/ via gh API identifies:
- 3 partial .dag files already in ctrl (workflows/review.dag etc.)
- ~17 TS subsystems with documented designs in scripts/session-dashboard/
- 4 in-flight algebra PRs #1192-#1197 (decomposition algebra series)
- Top-level constitutional docs (AGENTS/AUDIT/CODING/INVARIANTS/REVIEW_*/SCOPE_*/TESTING)

Plan structure:
- Phase 1: algebra substrate (dsl/std/process_algebra.dag)
- Phase 1.5: 5-8 parallel subsystem modeling PRs (doc-only, type-only)
  Items 1/3/4/5/6 can start NOW without Phase 1
- Phase 2: CLI projection to Rust binary
- Phase 3: HTTP/SQL/audit-event extdeps (R4 emission targets)
- Phase 4: ctrl/ cut-over per subsystem
- Phase 5: generalize

Proposes Ctrl-Migration Director parallel to gunbc R3-close Director;
3 Mgrs (Substrate/Subsystem-Modeling/Verification), Emission-Targets Mgr
spawned later. First-week concrete actions named.

6 open Qs for operator decision: file placement (gunbc vs ctrl), Director
shape, workflow-types dissolution scope, first migration target, ctrl PR
#1192-#1197 disposition, cross-Director coordination protocol.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(project-plan): comprehensive ctrl/ subsystem catalog (16 subsystems)

Per operator directive 2026-05-12T~18:55Z: audit ALL session-dashboard
work + identify what can migrate today. Gh-API audit of gunb-ai/ctrl
identified ~21,800 TS LOC across 16 subsystems.

Key findings:
- Existing demo precedent at research/.../inbox_delivery_slice.dag proves
  the `service` + typed-functions shape works today (~90% done already)
- 237 .mjs files in scripts/session-dashboard/ organized into ~16 subsystems
- ~20 .mjs in chatgpt-reviewer/ (browser DOM walking; partial-doable now)
- 3 .mjs in api-reviewer/ (CLI backend selection)
- 3 partial .dag in workflows/ (review, branch_review, review_config)

Strategy shift: model SERVICE CONTRACTS (types + typed function signatures
+ pure helpers), not just types. Demo proves it works today.

Subsystems classified:
- 8 items independent NOW (no Phase 1 dependency) — parallel first wave
- 6 items consume Phase 1 algebra substrate — second wave
- 2 items partial-NOW (chatgpt-reviewer browser, server HTTP routes)
- ~16 PRs total for Phase 1.5 (bundled by subsystem)

Operator-resolved Qs:
- Q-A: gunbc-side placement (dsl/ctrl/*.dag)
- Q-D: review-verdict already in flight per operator

New Qs added:
- Q-G: service-contract authority claim (future vs co vs substrate)
- Q-H: per-subsystem PR cadence (bundle by subsystem, ~16 PRs total)

First-wave dispatch updated: 8 workers parallel Day 2-5; 6 more Day 6-10.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(project-plan): replace-ASAP framing + parallel critical paths

Per operator directive 2026-05-12T~19:05Z: this is replacement, not
"future authority"; emission targets are critical-path parallel with
algebra substrate, not deferred. 4 Mgrs spawn Day 1 (not 3).

Changes:
- §1 Mission: replace dashboard ASAP; intent layer THIN, substrate
  rigor; compositional-modeling discipline (M9 DFS, lens-not-pass,
  cost-of-change = 1)
- §5 Program tree: orthogonal to zesty-bear-812 confirmed; 4 Mgrs
  (Substrate / Subsystem-Modeling / Emission-Targets / Verification)
  spawn together Day 1
- §6 Phase sequencing: Phase 1 + 1.5 + 3 in PARALLEL, all critical
  path. Per-subsystem cut-over fires as trio converges.
- §10 First-week actions: Emission-Targets Mgr spawns Day 1 not Day-N
- §11 Q-G RESOLVED: substrate becomes authority immediately when
  emission proves out per subsystem; no co-authority window

Three operator Qs resolved this session: A (gunbc-side), D (review-
verdict in flight), G (replace-immediately).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: address codex BLOCKING review #10331 (5 findings on PR #2775)

All 5 findings valid; substantive review, real gaps. Fixed in-place
rather than reply-without-fix.

Finding 1 — audit scope correction (LIVE V3 LENS SUBSTRATE):
prior audit scoped to dsl/std/ only; missed src/v3/std/lens.dag
(Director-locked 6-field Lens<C>) + src/v3/std/dimensions.dag:35
(Witness<Carrier> = Inhabits | Violates) + src/v3/std/coproduct_projection.dag
(Practice 4 dispatch substrate) + ~16 worked lens instances in
src/v3/lenses/. §3 mapping table corrected with these as ✓ EXISTS.

Finding 2 — workflow-types dissolution axis conflation:
§4 initial proposal conflated decomposition axis (Mode) with workflow
phase axis (IssueLifecycleStage). Corrected to preserve both as
structural coordinates (Mode × Phase product) per Practice 4 dimensional
dissolution. Phase open enum staged with dissolution trigger =
per-consumer enumeration. Until proof lands, workflow-types stay extant;
decomp-algebra co-located not replacing.

Finding 3 — Reopen/Regress operations added:
prior §6 claimed monotonicity (canCloseNode ≥ on composition) without
explicit reverse operations. Added Reopen { ReopenWitness } + Regress
{ RegressionWitness } operations with typed witness payloads. Replaced
monotonicity claim with closure-decision lattice: forward-stable subset
preserves; Reopen/Regress/Replan/Escalate explicitly retract closure
state with witnessed cause. No silent regression.

Finding 4 — staging discipline for catalog:
§3 catalog preamble corrected: every "doable NOW" row is STAGED with
explicit dissolution trigger, NOT authoritative-on-arrival. Trigger =
per-subsystem realization receipt + consumer parity (emission target
+ parity test + cut-over PR deletes TS). 🟡 STAGED until trigger fires.

Finding 5 — Practice 4 coverage widened:
§8 brief template gate 2 changed from "Practice 4 receipts on any open
enum" to "every enum/sum with ≥2 variants" (closed sums need
dissolution analysis too). Receipt format named (classification +
pattern + trigger). STOP criterion added: closed sum with no clear
dissolution pattern surfaces to Director.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(decomp-algebra): address codex inline BLOCKING — Lens/Witness parallel authority

Codex BLOCKING inline at docs/design-decomposition-algebra.md:154 + queued
companion: §5 Gap 2 proposed `Lens<S, A> { view, update }` and Gap 4
proposed `Witness { author, ... }` — both create parallel authority with
v3 substrate (Lens<C> at src/v3/std/lens.dag, Witness<C> at
src/v3/std/dimensions.dag:35).

Fixes per INVARIANTS P2 (single-authority) + MODELING.md M9 (DFS concept
DAG before defining):

1. Gap 2 RETRACTED — no new Lens carrier. State-projection in
   decomp-algebra reuses FreeMonoid<TimestampedEvent<Operation>> + fold
   (already in dsl/std/algebra.dag:390). If a future bidirectional-update
   use case surfaces, escalate to Substrate Mgr for shape audit.

2. Gap 4 RENAMED — decomp-algebra's "Witness" → "Attestation" to avoid
   name collision with v3 Witness<Carrier>. The carriers are
   structurally distinct (Attestation is human-intent attestation;
   v3 Witness<C> is per-Behavior inhabitance proof). Cascade applied:
   - Operation variants: attestation: Attestation
   - WitnessedOverride → AttestedOverride
   - ReopenWitness → ReopenAttestation
   - RegressionWitness → RegressionAttestation
   - Evidence enum → AttestationEvidence
   - StructuralLens → StructuralLensReceipt (refs v3 Lens<C> instance)
   - §7 dissolution receipt updated
   - §9 substrate skeleton updated
   - §13 worked example refs updated

Per feedback_self_hosting_md_authority_audit_before_substrate_naming.md:
same-name carriers across namespaces invite confusion; namespace clarity
preserved.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(decomp-algebra): preserve stage-bound pipeline facts (codex inline BLOCKING #2)

Codex BLOCKING inline at docs/design-decomposition-algebra.md:108: prior
dissolution proof would drop stage-bound pipeline coordinate facts
(StageRunKey, ClaimLease, SignalType, PipelineArtifact, ArtifactType,
MetricRecord) used downstream — violates P2 facts-flow-forward.

Grep verified at dsl/gunbc/workflow/types.dag:
- StageRunKey:159 — threads through StageOutcome / PipelineArtifact /
  MetricRecord / RetryDue / TerminalStateReached
- ClaimLease:166 — lease-execution claim
- SignalType:235 — idempotency-keyed signal payload tag
- PipelineArtifact:120,212-214 — stage-output artifact
- ArtifactType:214,226 — artifact taxonomy
- Metrics:225,318 — per-stage telemetry

Fix: only stage-VALUE collapses to (Mode, Phase); run-keyed pipeline
facts remain structurally distinct as forward-flowing coordinates.
Per feedback_projections_must_compose_facts.md + INVARIANTS P2.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(decomp-algebra): drop false monotonicity claim (codex inline BLOCKING #3)

Codex BLOCKING inline at docs/design-decomposition-algebra.md:231: prior
"forward-stable subset" framing was still false. Decompose adds children
→ retracts parent closure (COMPOSITE_HAS_OPEN_CHILDREN). Replan adds
reconcile child → same. Declare(Bucket) introduces BUCKET_NOT_DRAINED.
No Operation subset is universally monotonic in canCloseNode.

Fix: drop the monotonicity claim entirely. Replace with typed effects-
per-operation classification — each operation's effect on closure-
eligibility is type-signature-visible. Consumers MUST NOT assume
monotonicity across event-log composition.

Effects-per-operation classification added: Declare/Decompose/Drain/
Replan/Escalate/Pause/Reopen/Regress/AttestedOverride each with explicit
closure-eligibility effect (neutral / improves / retracts).

The only operational invariant retained: every closure-eligibility
transition is witnessed by an explicit Operation; no silent transitions.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(project-plan): correct authority claim per P2 staging discipline (codex inline BLOCKING #4)

Codex BLOCKING inline at docs/r4-ctrl-dag-migration-project-plan.md:61:
§3 strategy paragraph claimed "contract becomes authority from PR-merge"
which contradicted line 73 staging discipline AND violated INVARIANTS P2
(declarations alone are staging, not landed authority).

Fix: §3 strategy paragraph now explicitly states .dag files are 🟡 STAGED
on merge, NOT 🟢 AUTHORITY. Authority requires generated consumer or
emission target. Trio convergence (emission + parity + cut-over PR
deletes TS file) is the named dissolution trigger.

Consistent with feedback_no_textual_enforcement_bridges.md: textual
claims of authority don't substitute for structural enforcement.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(project-plan): Ctrl-Migration Director spawned + line 303 receipt scope (codex inline BLOCKING #5)

Two changes:

1. Codex BLOCKING at line 303: brief template scope bullet still said
   "Practice 4 receipts for any open enum" while acceptance gate #2 (line
   314) said "every enum/sum with ≥2 variants". Aligned scope bullet
   with gate per codex inline BLOCKING #5.

2. Operator directive 2026-05-12T~19:20Z: deep-wolf-155 operates at
   CEO/PM tier above gunbc R3-close Director zesty-bear-812. Ctrl-
   Migration Director spawned as CHILD under PM via dashboard-ops
   work-items create — node://adhoc-dc298bc7-9f7 (status=ready,
   2026-05-12T19:20:39Z). Auto-spawn fires within ~30s.

§5 tree updated to reflect:
- deep-wolf-155 (CEO/PM, root) above zesty-bear-812
- Ctrl-Migration Director as new child of deep-wolf-155
- PM owns inter-program coordination
- Each Director independent on program scope

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: C compiler + LLVM in .dag execution promotion plan

Per operator directive 2026-05-12T~19:30Z: parallel program plan to
ctrl-migration. Promotes existing research-viability artifacts at
~/ctrl/research/.../c-compiler-in-dag/ to executing production program.

Existing research is well-developed:
- PLAN.md (Brian-approved 2026-05-04 with A1-A10 locks)
- W0 shared IR primitives (5 files in extdeps/common/ir/)
- W4 LLVM IR spike (DONE — substrate + emit + types + trivial program)
- W7 XLS/Verilog spike (DONE)
- Phase-2 expression evaluator (DONE)
- 3 lens-counterfactual real-world bug case studies
- gunbc src/v3/lenses/ has 16 production lens instances ready to consume

This doc proposes the EXECUTION shape that consumes the research plan:
- Phase A (~1-2 weeks): promote research → production substrate
  (~6-9 PRs moving W0/W4/W7/phase-2-evaluator into gunbc dsl/extdeps/)
- Phase B (~6-12 months parallel): Frontend (W3a + W11) + IR (W2 + W2d)
  + Lens-Application (W8 + W10) + Pressure-Test
- Phase C (multi-month): emission targets (codegen, runtime, linker)
- Phase D (open-ended): "LLVM entirely" if pursued

Proposed program tree: NEW C-Compiler+LLVM Director under PM/CEO,
parallel to zesty-bear-812 (gunbc R3-close) + clever-ant-97 (ctrl-
migration). 5 Mgrs (Substrate, Frontend, IR, Lens-Application,
Pressure-Test).

Scope decision required (Q-A): interpretation (a) "C frontend + LLVM IR
substrate" (existing research scope; proposed) vs (b) "LLVM entirely"
(optimizer + codegen as .dag; multi-year).

6 open Qs for operator decision (§9).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(project-plan): Wave-1-trio checkpoint + staged-debt throttle (claude #10327 exploratory observations)

Per claude #10327 review observations on PR #2775 (APPROVE-with-exploratory):

1. "Ambitious blast radius for a plan in DRAFT; worth a checkpoint after
   Wave 1 lands one full trio (algebra ✓ + subsystem ✓ + emission ✓)
   before fanning the rest out, otherwise you risk 16 staged .dag files
   with no dissolution receipts firing."

   → §7 now requires WAVE-1-TRIO CHECKPOINT at ~Day 7-10 before Wave 2
   dispatch. If trio doesn't converge by Day 10, pause Wave 2 + surface
   to PM for re-scope.

2. "Parallel ≠ independent: Phase 1.5 PRs that land before their
   matching Phase 3 emission target are deliberately accepting staged-
   debt, and the Verification Mgr is the throttle."

   → §6 now states parallel-with-throttle explicitly. Verification Mgr
   enforces staged-debt budget: if 3+ subsystems merged with no matching
   emission, Subsystem-Modeling Mgr PAUSES new dispatch until catch-up.

Both observations were exploratory (review verdict was APPROVE not
BLOCKING), but substantive design feedback worth incorporating
structurally rather than acknowledging.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): remaining-work dependency graph + max-parallelization plan

Per operator directive 2026-05-12T~20:00Z: "define the remainder of R3
now, including all dependencies, so we can max parallelize all the work."

Comprehensive audit of §1.8 ledger:
- 102 R3-load-bearing gates total
- ~32 CLOSED (31%); ~40 IN-FLIGHT (39%); ~31 OPEN (30%)
- 2 lanes 100% done: T-Omni-Shape-B, T-Free-Consequences-Demonstration
- Standing gate #75 PASSING

Critical-path identified:
- Cluster M (T-Tests-As-Data-Completeness): gate #84 dissolves ~80-90 of
  101 SG-0 hand-Rust test entries in single closure. Phase 1 (#85/#86
  substrate) dispatch-ready NOW. Total 4-8w to full Cluster M closure.
- Cluster F (T-LP-Retirement): gates #81/#82/#83/#95 carve-promoted-IN-R3
  per Director 2026-05-09. F-α + F-β.1 parallel-dispatchable NOW.
  Total 3-4w to full Cluster F closure.

14 gates identified as dispatch-ready NOW (no prerequisite blocking).
Wave-1 dispatch plan covers 13-15 parallel workers across 3 R3 Mgrs.

Worker spawn capacity analysis:
- Substrate Mgr: 16 max, 1 active → +15 budget
- Debt-Paydown Mgr: 8 max, 0 active → +8 budget
- Verification Mgr: 8 max, 3 active → +5 budget
- Total +28 R3 spawn budget; currently at ~5; can scale 5-6x

Throughput levers ranked:
1. Land review-parser fix (eliminates per-PR PM bypass overhead)
2. Pre-author Wave-1 briefs in bulk
3. Spawn to Mgr capacity
4. Cluster M Phase 1 immediate dispatch (critical-path)
5. F-β.1 canvas immediate authoring
6. PB Mgr successor spawn (currently no active session)
7. Class-authorization batch merges (Director-ratified)

6 open Qs for operator decision.

Honest 6-8 week timeline to R3 close-ready with full Wave-1 dispatch
+ brief queue depth + parser fix landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
…wording (#2780)

* docs: decomposition-algebra modeling project (DRAFT)

Operator-supplied premise: project decomposition as algebra where children sum to parent meaning; walk-back when integration contradicts construction.

This draft formalizes:
- §1 The contradiction trigger (algebraic imbalance | claim contradiction)
- §2 Types sketch (Node, Claim, Decomposition, Witness, WalkBackEvent) — gunbc-lens-style; eventual home in dsl/std/ as MeaningDecomposition lens analogous to Cost lens
- §3 Walk-back algorithm (procedure with StableAncestor | RootContested termination)
- §4 Worked example — PR #2745 misread retroactively traced through procedure (2026-05-12 PM execution error)
- §5 Dashboard comms application sketch — message-as-walk-back-signal mapping
- §6 Open questions (coefficient semantics, claim equivalence, root-asker, rebalance cost, implementation surface)
- §7 Next step: validate on N=3-5 real cases before .dag formalization

Iteration expected.

* docs: decomposition-algebra rewrite for ctrl/ migration scoping

Replaces procedural walk-back draft (d534fd4) with structural-integration
shape per operator directive 2026-05-12: migrate ctrl/ processes into .dag
substrate; algebra is authoritative, ctrl/ TS becomes projected emission.

Audit-grounded with grep-verified citations across dsl/std/ + ctrl PR refs
(#1192/#1193/#1195/#1197). Identifies 4 modeling gaps (EventLog<T> primitive,
Lens<A,B> type, bounded multiplicity, unified Witness) + workflow-types
dissolution scope (dsl/gunbc/workflow/types.dag overlaps with decomp-algebra;
proposed dissolution rather than coexistence). First-cut migration target
recommended: review-verdict-parser (today's parser-lag pain validates the
heuristic-pass cost per feedback_lenses_not_passes).

Phase 1 substrate-file skeleton (~50 lines) sketched. Cost-of-change
contract = 1 file for new Mode variants / Operation arms.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(decomp-algebra): inline §13 validation case study; drop git-history cross-ref

Addresses claude #10308 review finding: §13's pointer to "previous draft in
git history at d534fd4" was a quirk for a brand-new file (per reviewer:
harmless but worth fixing). Inlines the PR #2745 misread walk-back trace
self-contained so readers don't need to git-log to follow the validation.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: ctrl/ → .dag migration project plan (parallel program tree)

Companion to docs/design-decomposition-algebra.md. Authored per operator
directive 2026-05-12: parallel program tree beside zesty-bear-812, model
dependencies, migrate as much ctrl/ as possible ASAP.

Audit of ctrl/ via gh API identifies:
- 3 partial .dag files already in ctrl (workflows/review.dag etc.)
- ~17 TS subsystems with documented designs in scripts/session-dashboard/
- 4 in-flight algebra PRs #1192-#1197 (decomposition algebra series)
- Top-level constitutional docs (AGENTS/AUDIT/CODING/INVARIANTS/REVIEW_*/SCOPE_*/TESTING)

Plan structure:
- Phase 1: algebra substrate (dsl/std/process_algebra.dag)
- Phase 1.5: 5-8 parallel subsystem modeling PRs (doc-only, type-only)
  Items 1/3/4/5/6 can start NOW without Phase 1
- Phase 2: CLI projection to Rust binary
- Phase 3: HTTP/SQL/audit-event extdeps (R4 emission targets)
- Phase 4: ctrl/ cut-over per subsystem
- Phase 5: generalize

Proposes Ctrl-Migration Director parallel to gunbc R3-close Director;
3 Mgrs (Substrate/Subsystem-Modeling/Verification), Emission-Targets Mgr
spawned later. First-week concrete actions named.

6 open Qs for operator decision: file placement (gunbc vs ctrl), Director
shape, workflow-types dissolution scope, first migration target, ctrl PR
#1192-#1197 disposition, cross-Director coordination protocol.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(project-plan): comprehensive ctrl/ subsystem catalog (16 subsystems)

Per operator directive 2026-05-12T~18:55Z: audit ALL session-dashboard
work + identify what can migrate today. Gh-API audit of gunb-ai/ctrl
identified ~21,800 TS LOC across 16 subsystems.

Key findings:
- Existing demo precedent at research/.../inbox_delivery_slice.dag proves
  the `service` + typed-functions shape works today (~90% done already)
- 237 .mjs files in scripts/session-dashboard/ organized into ~16 subsystems
- ~20 .mjs in chatgpt-reviewer/ (browser DOM walking; partial-doable now)
- 3 .mjs in api-reviewer/ (CLI backend selection)
- 3 partial .dag in workflows/ (review, branch_review, review_config)

Strategy shift: model SERVICE CONTRACTS (types + typed function signatures
+ pure helpers), not just types. Demo proves it works today.

Subsystems classified:
- 8 items independent NOW (no Phase 1 dependency) — parallel first wave
- 6 items consume Phase 1 algebra substrate — second wave
- 2 items partial-NOW (chatgpt-reviewer browser, server HTTP routes)
- ~16 PRs total for Phase 1.5 (bundled by subsystem)

Operator-resolved Qs:
- Q-A: gunbc-side placement (dsl/ctrl/*.dag)
- Q-D: review-verdict already in flight per operator

New Qs added:
- Q-G: service-contract authority claim (future vs co vs substrate)
- Q-H: per-subsystem PR cadence (bundle by subsystem, ~16 PRs total)

First-wave dispatch updated: 8 workers parallel Day 2-5; 6 more Day 6-10.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(project-plan): replace-ASAP framing + parallel critical paths

Per operator directive 2026-05-12T~19:05Z: this is replacement, not
"future authority"; emission targets are critical-path parallel with
algebra substrate, not deferred. 4 Mgrs spawn Day 1 (not 3).

Changes:
- §1 Mission: replace dashboard ASAP; intent layer THIN, substrate
  rigor; compositional-modeling discipline (M9 DFS, lens-not-pass,
  cost-of-change = 1)
- §5 Program tree: orthogonal to zesty-bear-812 confirmed; 4 Mgrs
  (Substrate / Subsystem-Modeling / Emission-Targets / Verification)
  spawn together Day 1
- §6 Phase sequencing: Phase 1 + 1.5 + 3 in PARALLEL, all critical
  path. Per-subsystem cut-over fires as trio converges.
- §10 First-week actions: Emission-Targets Mgr spawns Day 1 not Day-N
- §11 Q-G RESOLVED: substrate becomes authority immediately when
  emission proves out per subsystem; no co-authority window

Three operator Qs resolved this session: A (gunbc-side), D (review-
verdict in flight), G (replace-immediately).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: address codex BLOCKING review #10331 (5 findings on PR #2775)

All 5 findings valid; substantive review, real gaps. Fixed in-place
rather than reply-without-fix.

Finding 1 — audit scope correction (LIVE V3 LENS SUBSTRATE):
prior audit scoped to dsl/std/ only; missed src/v3/std/lens.dag
(Director-locked 6-field Lens<C>) + src/v3/std/dimensions.dag:35
(Witness<Carrier> = Inhabits | Violates) + src/v3/std/coproduct_projection.dag
(Practice 4 dispatch substrate) + ~16 worked lens instances in
src/v3/lenses/. §3 mapping table corrected with these as ✓ EXISTS.

Finding 2 — workflow-types dissolution axis conflation:
§4 initial proposal conflated decomposition axis (Mode) with workflow
phase axis (IssueLifecycleStage). Corrected to preserve both as
structural coordinates (Mode × Phase product) per Practice 4 dimensional
dissolution. Phase open enum staged with dissolution trigger =
per-consumer enumeration. Until proof lands, workflow-types stay extant;
decomp-algebra co-located not replacing.

Finding 3 — Reopen/Regress operations added:
prior §6 claimed monotonicity (canCloseNode ≥ on composition) without
explicit reverse operations. Added Reopen { ReopenWitness } + Regress
{ RegressionWitness } operations with typed witness payloads. Replaced
monotonicity claim with closure-decision lattice: forward-stable subset
preserves; Reopen/Regress/Replan/Escalate explicitly retract closure
state with witnessed cause. No silent regression.

Finding 4 — staging discipline for catalog:
§3 catalog preamble corrected: every "doable NOW" row is STAGED with
explicit dissolution trigger, NOT authoritative-on-arrival. Trigger =
per-subsystem realization receipt + consumer parity (emission target
+ parity test + cut-over PR deletes TS). 🟡 STAGED until trigger fires.

Finding 5 — Practice 4 coverage widened:
§8 brief template gate 2 changed from "Practice 4 receipts on any open
enum" to "every enum/sum with ≥2 variants" (closed sums need
dissolution analysis too). Receipt format named (classification +
pattern + trigger). STOP criterion added: closed sum with no clear
dissolution pattern surfaces to Director.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(decomp-algebra): address codex inline BLOCKING — Lens/Witness parallel authority

Codex BLOCKING inline at docs/design-decomposition-algebra.md:154 + queued
companion: §5 Gap 2 proposed `Lens<S, A> { view, update }` and Gap 4
proposed `Witness { author, ... }` — both create parallel authority with
v3 substrate (Lens<C> at src/v3/std/lens.dag, Witness<C> at
src/v3/std/dimensions.dag:35).

Fixes per INVARIANTS P2 (single-authority) + MODELING.md M9 (DFS concept
DAG before defining):

1. Gap 2 RETRACTED — no new Lens carrier. State-projection in
   decomp-algebra reuses FreeMonoid<TimestampedEvent<Operation>> + fold
   (already in dsl/std/algebra.dag:390). If a future bidirectional-update
   use case surfaces, escalate to Substrate Mgr for shape audit.

2. Gap 4 RENAMED — decomp-algebra's "Witness" → "Attestation" to avoid
   name collision with v3 Witness<Carrier>. The carriers are
   structurally distinct (Attestation is human-intent attestation;
   v3 Witness<C> is per-Behavior inhabitance proof). Cascade applied:
   - Operation variants: attestation: Attestation
   - WitnessedOverride → AttestedOverride
   - ReopenWitness → ReopenAttestation
   - RegressionWitness → RegressionAttestation
   - Evidence enum → AttestationEvidence
   - StructuralLens → StructuralLensReceipt (refs v3 Lens<C> instance)
   - §7 dissolution receipt updated
   - §9 substrate skeleton updated
   - §13 worked example refs updated

Per feedback_self_hosting_md_authority_audit_before_substrate_naming.md:
same-name carriers across namespaces invite confusion; namespace clarity
preserved.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(decomp-algebra): preserve stage-bound pipeline facts (codex inline BLOCKING #2)

Codex BLOCKING inline at docs/design-decomposition-algebra.md:108: prior
dissolution proof would drop stage-bound pipeline coordinate facts
(StageRunKey, ClaimLease, SignalType, PipelineArtifact, ArtifactType,
MetricRecord) used downstream — violates P2 facts-flow-forward.

Grep verified at dsl/gunbc/workflow/types.dag:
- StageRunKey:159 — threads through StageOutcome / PipelineArtifact /
  MetricRecord / RetryDue / TerminalStateReached
- ClaimLease:166 — lease-execution claim
- SignalType:235 — idempotency-keyed signal payload tag
- PipelineArtifact:120,212-214 — stage-output artifact
- ArtifactType:214,226 — artifact taxonomy
- Metrics:225,318 — per-stage telemetry

Fix: only stage-VALUE collapses to (Mode, Phase); run-keyed pipeline
facts remain structurally distinct as forward-flowing coordinates.
Per feedback_projections_must_compose_facts.md + INVARIANTS P2.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(decomp-algebra): drop false monotonicity claim (codex inline BLOCKING #3)

Codex BLOCKING inline at docs/design-decomposition-algebra.md:231: prior
"forward-stable subset" framing was still false. Decompose adds children
→ retracts parent closure (COMPOSITE_HAS_OPEN_CHILDREN). Replan adds
reconcile child → same. Declare(Bucket) introduces BUCKET_NOT_DRAINED.
No Operation subset is universally monotonic in canCloseNode.

Fix: drop the monotonicity claim entirely. Replace with typed effects-
per-operation classification — each operation's effect on closure-
eligibility is type-signature-visible. Consumers MUST NOT assume
monotonicity across event-log composition.

Effects-per-operation classification added: Declare/Decompose/Drain/
Replan/Escalate/Pause/Reopen/Regress/AttestedOverride each with explicit
closure-eligibility effect (neutral / improves / retracts).

The only operational invariant retained: every closure-eligibility
transition is witnessed by an explicit Operation; no silent transitions.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(project-plan): correct authority claim per P2 staging discipline (codex inline BLOCKING #4)

Codex BLOCKING inline at docs/r4-ctrl-dag-migration-project-plan.md:61:
§3 strategy paragraph claimed "contract becomes authority from PR-merge"
which contradicted line 73 staging discipline AND violated INVARIANTS P2
(declarations alone are staging, not landed authority).

Fix: §3 strategy paragraph now explicitly states .dag files are 🟡 STAGED
on merge, NOT 🟢 AUTHORITY. Authority requires generated consumer or
emission target. Trio convergence (emission + parity + cut-over PR
deletes TS file) is the named dissolution trigger.

Consistent with feedback_no_textual_enforcement_bridges.md: textual
claims of authority don't substitute for structural enforcement.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(project-plan): Ctrl-Migration Director spawned + line 303 receipt scope (codex inline BLOCKING #5)

Two changes:

1. Codex BLOCKING at line 303: brief template scope bullet still said
   "Practice 4 receipts for any open enum" while acceptance gate #2 (line
   314) said "every enum/sum with ≥2 variants". Aligned scope bullet
   with gate per codex inline BLOCKING #5.

2. Operator directive 2026-05-12T~19:20Z: deep-wolf-155 operates at
   CEO/PM tier above gunbc R3-close Director zesty-bear-812. Ctrl-
   Migration Director spawned as CHILD under PM via dashboard-ops
   work-items create — node://adhoc-dc298bc7-9f7 (status=ready,
   2026-05-12T19:20:39Z). Auto-spawn fires within ~30s.

§5 tree updated to reflect:
- deep-wolf-155 (CEO/PM, root) above zesty-bear-812
- Ctrl-Migration Director as new child of deep-wolf-155
- PM owns inter-program coordination
- Each Director independent on program scope

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: C compiler + LLVM in .dag execution promotion plan

Per operator directive 2026-05-12T~19:30Z: parallel program plan to
ctrl-migration. Promotes existing research-viability artifacts at
~/ctrl/research/.../c-compiler-in-dag/ to executing production program.

Existing research is well-developed:
- PLAN.md (Brian-approved 2026-05-04 with A1-A10 locks)
- W0 shared IR primitives (5 files in extdeps/common/ir/)
- W4 LLVM IR spike (DONE — substrate + emit + types + trivial program)
- W7 XLS/Verilog spike (DONE)
- Phase-2 expression evaluator (DONE)
- 3 lens-counterfactual real-world bug case studies
- gunbc src/v3/lenses/ has 16 production lens instances ready to consume

This doc proposes the EXECUTION shape that consumes the research plan:
- Phase A (~1-2 weeks): promote research → production substrate
  (~6-9 PRs moving W0/W4/W7/phase-2-evaluator into gunbc dsl/extdeps/)
- Phase B (~6-12 months parallel): Frontend (W3a + W11) + IR (W2 + W2d)
  + Lens-Application (W8 + W10) + Pressure-Test
- Phase C (multi-month): emission targets (codegen, runtime, linker)
- Phase D (open-ended): "LLVM entirely" if pursued

Proposed program tree: NEW C-Compiler+LLVM Director under PM/CEO,
parallel to zesty-bear-812 (gunbc R3-close) + clever-ant-97 (ctrl-
migration). 5 Mgrs (Substrate, Frontend, IR, Lens-Application,
Pressure-Test).

Scope decision required (Q-A): interpretation (a) "C frontend + LLVM IR
substrate" (existing research scope; proposed) vs (b) "LLVM entirely"
(optimizer + codegen as .dag; multi-year).

6 open Qs for operator decision (§9).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(project-plan): Wave-1-trio checkpoint + staged-debt throttle (claude #10327 exploratory observations)

Per claude #10327 review observations on PR #2775 (APPROVE-with-exploratory):

1. "Ambitious blast radius for a plan in DRAFT; worth a checkpoint after
   Wave 1 lands one full trio (algebra ✓ + subsystem ✓ + emission ✓)
   before fanning the rest out, otherwise you risk 16 staged .dag files
   with no dissolution receipts firing."

   → §7 now requires WAVE-1-TRIO CHECKPOINT at ~Day 7-10 before Wave 2
   dispatch. If trio doesn't converge by Day 10, pause Wave 2 + surface
   to PM for re-scope.

2. "Parallel ≠ independent: Phase 1.5 PRs that land before their
   matching Phase 3 emission target are deliberately accepting staged-
   debt, and the Verification Mgr is the throttle."

   → §6 now states parallel-with-throttle explicitly. Verification Mgr
   enforces staged-debt budget: if 3+ subsystems merged with no matching
   emission, Subsystem-Modeling Mgr PAUSES new dispatch until catch-up.

Both observations were exploratory (review verdict was APPROVE not
BLOCKING), but substantive design feedback worth incorporating
structurally rather than acknowledging.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): remaining-work dependency graph + max-parallelization plan

Per operator directive 2026-05-12T~20:00Z: "define the remainder of R3
now, including all dependencies, so we can max parallelize all the work."

Comprehensive audit of §1.8 ledger:
- 102 R3-load-bearing gates total
- ~32 CLOSED (31%); ~40 IN-FLIGHT (39%); ~31 OPEN (30%)
- 2 lanes 100% done: T-Omni-Shape-B, T-Free-Consequences-Demonstration
- Standing gate #75 PASSING

Critical-path identified:
- Cluster M (T-Tests-As-Data-Completeness): gate #84 dissolves ~80-90 of
  101 SG-0 hand-Rust test entries in single closure. Phase 1 (#85/#86
  substrate) dispatch-ready NOW. Total 4-8w to full Cluster M closure.
- Cluster F (T-LP-Retirement): gates #81/#82/#83/#95 carve-promoted-IN-R3
  per Director 2026-05-09. F-α + F-β.1 parallel-dispatchable NOW.
  Total 3-4w to full Cluster F closure.

14 gates identified as dispatch-ready NOW (no prerequisite blocking).
Wave-1 dispatch plan covers 13-15 parallel workers across 3 R3 Mgrs.

Worker spawn capacity analysis:
- Substrate Mgr: 16 max, 1 active → +15 budget
- Debt-Paydown Mgr: 8 max, 0 active → +8 budget
- Verification Mgr: 8 max, 3 active → +5 budget
- Total +28 R3 spawn budget; currently at ~5; can scale 5-6x

Throughput levers ranked:
1. Land review-parser fix (eliminates per-PR PM bypass overhead)
2. Pre-author Wave-1 briefs in bulk
3. Spawn to Mgr capacity
4. Cluster M Phase 1 immediate dispatch (critical-path)
5. F-β.1 canvas immediate authoring
6. PB Mgr successor spawn (currently no active session)
7. Class-authorization batch merges (Director-ratified)

6 open Qs for operator decision.

Honest 6-8 week timeline to R3 close-ready with full Wave-1 dispatch
+ brief queue depth + parser fix landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: fix cursor #10356 findings — correct INVARIANTS labels + Phase A scope wording

Both BLOCKING findings on already-merged PR #2775 (cursor/composer-2 review #10356):

1. docs/design-decomposition-algebra.md:492 — INVARIANTS labels were wrong:
   - P1 is "Modeling Faithfulness" (single-authority is a consequence)
   - P2 is "Boundary Discipline" (illegal-states-unrepresentable is
     docs/modeling-discipline.md Practice 2, downstream of P2)
   - P5 is "Progress Is Dissolution" (Pure Bootstrap is the separate
     docs/design-pure-bootstrap-zero.md thesis)

2. docs/r4-c-compiler-and-llvm-in-dag-program-plan.md:246 — §8 said
   Phase A is "doc-shape promotion only" but §3 describes ~6-9 PRs
   promoting .dag substrate into dsl/extdeps/. Reconciled: "no compiler
   runtime code in Phase A" — typed .dag substrate promotion IS the work
   (real tree additions); Rust runtime / parser-emitter execution /
   codegen invocation are Phase B / Phase C scope.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant