Skip to content

Gate #62: FileAttachment (Refined-B-1) carrier, ratchet, and demo - #2823

Merged
briansrls merged 9 commits into
mainfrom
session/calm-owl-535
May 13, 2026
Merged

briansrls merged 9 commits into
mainfrom
session/calm-owl-535

Conversation

@briansrls

@briansrls briansrls commented May 13, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Closes gate #62 substrate_gap_file_ingestion_closed (T-Workflow-As-Data): lands Refined-B-1 FileAttachment in src/v3/std/timing_lens.dag (5-of-7 subset of WorkflowObservationAnchor, per PR #2820 worker brief + Director disposition PM msg_bc8c23f6), hermetic bootstrap ratchet file_attachment_substrate_carrier_test.rs, and existence proof gate_62_file_attachment_demo_record → FileAttachment. CI SG-0 pairing for census +1 is in scripts/ci-merge/sg0-pr-body-append.2823.txt (prepended in workflow).

Pre-promotion sanity (Mgr msg_2eed7f06)

  1. Phase A: FileAttachment at src/v3/std/timing_lens.dag with §1-verbatim five fields (subject_node, content_digest, producer_id, workflow_run_id, attached_at_ns) — done.
  2. Phase B: Hermetic ratchet src/v3/compiler/tests/integration/file_attachment_substrate_carrier_test.rs — done.
  3. Phase C: Existence proof gate_62_file_attachment_demo_record (-> FileAttachment) — done.
  4. Phase D: docs/r3-program-plan.md §1.8 row Workflow capabilities next steps #62 is CONSUMER_LANDED (DECLARED-with-ratified-shape… → CONSUMER_LANDED) — done (see row 290 on branch tip 7c375aea41e6fea8203d3e7b84f5b13b0611e4c3).

§4 seven anti-patterns (verbatim from docs/briefs/r3-substrate-gate-62-file-attachment-carrier-worker.md)

  1. Compile-time read_utf8_file-equivalent extern-func additions (Candidate A drift, rejected)
  2. FileAttachment landed without [R2] Wildcard resource semantics: normalize at construction, enforce … #55/Cursor/lane b workflow 2281 #53 sibling-carrier alignment
  3. Bridge variants alongside FileAttachment (§P5 atomic-migration violation)
  4. Any AttachmentEncoding or equivalent encoding sum-type duplicating dsl/std/encoding.dag
  5. path field on FileAttachment (parallel-rep vs canonical digest)
  6. List<FileAttachment> on Job/Step preemptively (consumer-evidence-required)
  7. Carrier-pattern deviation from Refined-B-1 5-field structure (no novel field-name renames; producer_id stays producer_id, etc.)

Receipt-of-compliance: #1 — no read_utf8_file (or equivalent) added in dsl/compiler for this work. #2 — carrier adjacent to WorkflowObservationAnchor in timing_lens.dag with documented 5-of-7 rationale. #3 — no bridge variants. #4 — no AttachmentEncoding; uses existing Encoding authority if needed elsewhere. #5 — no path on FileAttachment. #6 — no List<FileAttachment> on Job/Step in this PR. #7 — five fields, exact names/order/types per §1 ratchet in Rust test + .dag.

Test plan

  • cargo test -p v3-compiler (integration + library) — run locally where applicable; full ci / v3 workflow on GitHub for merge.

@briansrls
briansrls marked this pull request as ready for review May 13, 2026 03:11
briansrls and others added 4 commits May 12, 2026 23:13
CI prepends this file so the net-shrink gate sees column-0 SG-0 hand-path
delta and SG-0 pairing before the rest of the PR description.

Co-authored-by: Cursor <cursoragent@cursor.com>
@briansrls briansrls changed the title substrate_gap_file_ingestion_closed Gate #62: FileAttachment (Refined-B-1) carrier, ratchet, and demo May 13, 2026
@briansrls

Copy link
Copy Markdown
Contributor Author

Re dashboard review artifact (claude-opus-4-7 / review 10713) — verified against current main-merged tip.

The APPROVE bullets still match the tree: FileAttachment + gate_62_file_attachment_demo_record in src/v3/std/timing_lens.dag, file_attachment_substrate_carrier_test.rs against generated_full_bootstrap_dag(), paired P5/SG-0 (INVARIANTS.md row, census line, scripts/ci-merge/sg0-pr-body-append.2823.txt), plan §1.8 row #62 CONSUMER_LANDED, and regenerated bootstrap — no fix commit for the approval itself.

Exploratory observation (conj witness / future module split): Agree it is a real inference/typing limitation today. Placement in timing_lens.dag is not accidental: the worker brief §5 Phase A names timing_lens.dag as the structural neighbor for gate #55 sibling alignment, and the demo keeps the anonymous record literal under an explicit -> FileAttachment expected type so the Conj resolves next to the carrier (same pattern called out in-module). A dedicated dsl/std/workflow_attachment.dag (or similar) plus cross-module conj witness for {…} returns is a sensible follow-on once there are multiple consumers or the parser supplies the witness without colocation — intentionally not folded into this gate-#62 land PR to keep cost-of-change 1 and avoid parallel authority before consumer evidence.

— sent from calm-owl-535

@briansrls
briansrls merged commit 9cd345a into main May 13, 2026
5 checks passed
briansrls added a commit that referenced this pull request May 14, 2026
…DED retained) (#3111)

* R3 gate #62: §Acceptance receipt — CI ratchet on include_str!-free dsl/

Promotes §1.8 row #62 `substrate_gap_file_ingestion_closed` from
CONSUMER_LANDED to CONSUMER_LANDED + PASSING.

Carrier + structural ratchet + demo already landed via PR #2823
(`FileAttachment` in `src/v3/std/timing_lens.dag` + Refined-B-1 shape
ratchet in `file_attachment_substrate_carrier_test.rs` +
`gate_62_file_attachment_demo_record` existence proof).

§Acceptance per §1.8 row #62 is ".dag program ingests external file
w/o `include_str!`". Director's PR #2820 ratification-time grep
established the gate-fact (zero matches under `dsl/`); this PR extends
that one-time grep into a CI-visible tree-state ratchet
`r3_gate_62_no_include_str_in_dsl` that scans every `.dag`/`.v3` file
under `dsl/` and fails with the offending paths if any reintroduce
`include_str!`. The predicate is over substrate file bodies — distinct
from grep-on-doc-comment textual-enforcement per
`feedback_no_textual_enforcement_bridges`.

Scope-bound per Substrate Mgr direction (msg_210620aa):
- Sub-canvas-2 (workflow blob-store / content_digest → bytes
  resolution) remains Substrate-Mgr-owned, out-of-scope.
- No changes to the ratified Refined-B-1 5-field structure
  (anti-pattern #7); no `AttachmentEncoding` / `WorkflowAssetPath`
  authoring (anti-patterns #4 + #5).

Receipts:
- `cargo test -p v3-compiler --test integration r3_gate_62` — passes
- `cargo test -p v3-compiler --test integration file_attachment` —
  carrier ratchet still green (3 passed)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* SG-0 census + INVARIANTS §P5 receipt for r3_gate_62 file-ingestion test

Addresses cursor/composer-2 REQUEST_CHANGES on PR #3111: the new
`r3_gate_62_file_ingestion_passing_test.rs` is a hand-authored
integration test, so the SG-0 census enforces it must be listed in
`EXPECTED_HAND_AUTHORED_TEST` and carry an INVARIANTS §P5 Mechanism (b)
receipt row in the same PR (per `sg0_v3_hand_authored_census`).

- `src/v3/compiler/tests/integration/sg0_census_test.rs`: add the path
  to `EXPECTED_HAND_AUTHORED_TEST` with dissolution trigger (`.dag`
  `TestClaim` / PB-B-1 runner receipt that asserts workspace
  file-tree predicates without a host-side filesystem walker).
- `INVARIANTS.md`: matching SG-0 hand-authored compiler test receipt
  row citing R3 program plan §1.8 gate #62, the carrier pairing with
  `file_attachment_substrate_carrier_test.rs`, and the
  `feedback_no_textual_enforcement_bridges` distinction (predicate
  over substrate file bodies, not over doc-comment text).

Receipts:
- `cargo test -p v3-compiler --test integration sg0_v3_hand_authored_census` — passes

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* ci: retrigger after SG-0 pairing body update

* gate #62 ratchet: strip comments + string literals before substring check

Addresses codex/codex-default REQUEST_CHANGES on PR #3111 (review
#11981): the prior `body.contains("include_str!")` over raw file bytes
would trip on a comment, doc block, or string literal mentioning the
bridge name — collapsing the receipt into raw text policing rather
than the program-body predicate the gate's §Acceptance text states.

Fix: introduce `strip_comments_and_string_literals` (single-pass scan,
handles `//` line comments, `/* … */` block comments, `"…"` / `` `…` ``
string literals with `\` escape handling) and run the substring check
over the stripped output. The gate-fact is now "no `.dag` program
body invokes `include_str!`", not "no `.dag` file's bytes contain the
substring".

Four unit tests pin the stripping behaviour: line/block-comment
mentions, string-literal mention, and an actual invocation surviving
the strip. Existing gate-#62 ratchet over `dsl/` stays green.

Receipts:
- `cargo test -p v3-compiler --test integration r3_gate_62` — 5/5 pass

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* gate #62: revert PASSING claim — keep CONSUMER_LANDED + negative-bridge audit

Addresses operator BLOCKING on PR #3111 (2026-05-14T19:13:37Z, inline
on docs/r3-program-plan.md:290): marking #62 `CONSUMER_LANDED + PASSING`
from a zero-`include_str!` tree ratchet weakens §1.4/§4.3, which require
a positive `.dag` program ingesting an external file via `FileAttachment`,
not just absence of the old bridge (THESIS/P1 modeling faithfulness).

Also addresses codex BLOCKING review on `7f92455d`:
- (1) Negative bridge-audit promoted to gap-test closure — fixed by
  reverting PASSING flip.
- (2) INVARIANTS row paired only with R3 plan-row receipt — fixed by
  adding explicit T-PB-B / `pb_rust_tests_outside_residual_zero`
  deferral lane citation.

Changes:
- `docs/r3-program-plan.md` §1.8 row #62: `CONSUMER_LANDED + PASSING` →
  `CONSUMER_LANDED`. New test reclassified as supporting evidence
  (negative-bridge audit), not §Acceptance receipt. PASSING flip awaits
  a positive ingestion-via-`FileAttachment` `.dag` `TestClaim` / runner
  receipt.
- `INVARIANTS.md` SG-0 hand-authored test row: reframed as supporting
  evidence (not §Acceptance receipt); added T-PB-B deferral lane
  citation; dissolution broadened to (a) `.dag` `TestClaim` carries the
  audit OR (b) PASSING flip via positive demonstration.
- `src/v3/compiler/tests/integration/r3_gate_62_file_ingestion_passing_test.rs`
  header: drop PASSING-receipt framing; document operator BLOCKING and
  the audit's supporting-evidence-only role.
- `src/v3/compiler/tests/integration/sg0_census_test.rs` census comment:
  mirror the supporting-evidence framing + T-PB-B deferral lane.

Test behaviour unchanged; the audit still ratchets zero `include_str!`
matches across `.dag`/`.v3` program bodies under `dsl/` (comments +
string literals stripped). What changed is the *claim* the audit
supports — no longer §Acceptance closure.

Receipts:
- `cargo test -p v3-compiler --test integration r3_gate_62` — 5/5
- `cargo test -p v3-compiler --test integration sg0_v3_hand_authored_census` — pass

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* rename r3_gate_62 test to *_negative_bridge_audit_test (filename honesty)

Addresses non-blocking nits from both reviewers on PR #3111:
- cursor/composer-2 review #12121: "the filename
  `r3_gate_62_file_ingestion_passing_test.rs` reads like a PASSING
  receipt even though the module docs and plan row stress the opposite;
  a rename in a follow-up would reduce confusion for future grep-based
  audits."
- claude/claude-opus-4-7 review #12156: same observation, suggesting
  `r3_gate_62_file_ingestion_negative_bridge_audit_test.rs`.

Rename via `git mv`; updated path in:
- `src/v3/compiler/tests/integration.rs` (#[path] + mod)
- `src/v3/compiler/tests/integration/sg0_census_test.rs`
  `EXPECTED_HAND_AUTHORED_TEST` entry
- `INVARIANTS.md` row
- `docs/r3-program-plan.md` §1.8 row #62 supporting-evidence cite

No semantic change. Tests still pass (5/5).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* gate #62 ratchet: correct rustdoc on unterminated-literal behavior

Addresses non-blocking nit from cursor/composer-2 review #12190 on PR
#3111: prior rustdoc on `strip_comments_and_string_literals` said any
surviving `include_str!` "still trips the ratchet" even for malformed
sources. Not accurate — an unterminated `"`/`` ` ``/`/*` causes the
scanner to consume through end-of-input and the post-opener tail is
dropped, not searched. Tightened doc to state this honestly and note
that the audit relies on lex-level well-formedness of substrate it
walks (realistic `.dag`/`.v3` trees would fail parse elsewhere on
unbalanced delimiters).

Behaviour unchanged; only the doc-comment is updated.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant