Repository navigation
v4: structural scaffold + R3+R4 audit migration + ratifications - #3147
Conversation
Coordinated CI policy change to support the v4 program (PR #3147): both v2 and v3 are now frozen-buildable — workspace members that build on demand but only run their heavy CI when their source is touched (or on push-to-main for trunk verification). ## Changes **Cargo.toml**: re-add `src/v2/stage0` + `src/v2/tests` to workspace members, plus the `[profile.dev.package.v2-compiler]` block that v2's Rc-aware stage0 needs (debug-assertions = false, opt-level = 2). Verified locally: `cargo build -p v2-compiler --release` builds clean in ~1m, no bitrot. **.github/workflows/ci.yml**: - New `affected` job: runs first (~30s), computes `v2`/`v3` outputs by diffing against origin/main (or HEAD~1 on push). Other jobs depend on its outputs. - New `v2` job: runs `bootstrap_fixed_point --ignored` test only when src/v2/ or workspace deps are affected. Verifies v2's self-host property is preserved across any v2 modification. - `v3` job: gated at top level — runs only when src/v3/, dsl/, or workspace deps affected, OR push-to-main. Effectively freezes v3 on PRs that don't touch it (the typical case during v4 development). - v3-specific steps inside the shared `ci` job (bootstrap snapshot freshness gate, gate #103 path-regex inventory + integration tests) are gated on the same condition. - `self_host_ratchet` job: now tolerates v3 being skipped (treats result=skipped as a valid no-op rather than a failure). **scripts/detect-affected-components.sh**: new script that does the git-diff-based detection. Lives outside ci.yml so it doesn't trip gate #103's `workflow_no_path_regex_policy_ci_yml` policy (which forbids path-selection substrings inside .github/workflows/*.yml). Single authority: when v3 is unfrozen and the v3 affected-set lens becomes canonical again, this script can be replaced by an invocation of that lens — workflow integration point stays the same. ## Why this shape - v2 is restored as comparison artifact + v4 bootstrap source. Editing v2 is rare but allowed; when it happens, fixed-point must hold. - v3 is frozen pending the v4 program. Most PRs (v4 work, docs, process changes) don't touch v3 — gating skips the heavy v3 build/ test (saves ~10-15min per PR). - Both v2 and v3 are still in workspace so `cargo build --workspace` works for development; CI only invokes them via `-p` when affected. - push-to-main always runs both v2 and v3 CI as trunk safety net, even when nothing in v2/v3 changed (catches dep-bump regressions). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…view Per operator review of PR #3147 v4 scaffold against THESIS coverage: ## Added file - compiler/00_compile.dag — pipeline orchestrator (Source, TargetSpec) -> Result<TargetSource, Diagnostic>. Wires tokenize → parse → normalize → resolve → infer → emit. Mirrors v2's compile.dag pattern. Without this file there was no v4 home for the top-level compile() function — bin/main.dag (trampoline) needs something to call. Bundled with T-10 (emit) since the orchestrator is consumer of every prior stage. ## Architectural commitments (new STRUCTURE.md section) Three substrate-level decisions ratified during review, captured in STRUCTURE.md so per-task briefs can reference them: 1. TypeNode and Behavior are CLOSED enums (C1 stop-signal, THESIS:202). Substrate extension requires explicit operator ratification. Closure enforced in std/node.dag itself, not by review process — the compiler reads the closed enum and refuses programs that synthesize outside it. 2. Tier 2 partial-op totalization lives in std/primitive.dag (THESIS:175-176). Each primitive declares its partial ops' totalization shape (Result-return / Witness-return / refinement- precondition) inline, no separate registry. 3. Diagnostic schema includes suggested_correction (THESIS:103-105 "show the correct code"). Schema: Diagnostic { reason, at, suggested_correction: Option<NodeFragment> }. Lenses populate where structurally possible; absent fix is None, not a missing field. ## Updated counts - 28 → 29 .dag files - 31 → 32 total files at scaffold time - compiler/ now has 7 files (orchestrator + 6 stages) ## Deferred to follow-up PR Per operator request: pre-declared impossible-bug TestClaim scaffolds (one TestClaim file per R1 class from THESIS:373-389) go in a separate PR after this merges, for focused review. ## Pending operator decision (not in this commit) extdeps/io.dag (or extdeps/process.dag + extdeps/file.dag) — v4 needs an I/O substrate to function as a self-hosting compiler at all (read source files, write emitted target files, ExecuteCommand for boundary tests per THESIS facet 3, Shape B user-program emitters). Naming + single-vs-split decision pending in PR conversation. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Per operator review of PR #3147 conversation, applies the substrate- grounding discipline (feedback_modeling_philosophy + feedback_epistemic_ stacking) structurally: every v4 .dag file now carries an # Anchor: header line citing the canonical reference its modeling derives from. ## New files (extdeps/) - extdeps/process.dag — Anchor: https://en.wikipedia.org/wiki/Process_(computing) Models OS process: Process, ProcessId (PID), ProcessState (Running | Exited(ExitCode) | Signaled(SignalNum)), Command, spawn/wait/capture operations. Grounded in POSIX/SUS process model. - extdeps/file_system.dag — Anchor: https://en.wikipedia.org/wiki/File_system + POSIX File and Directory Operations. Models Path (Absolute|Relative), PathComponent (NonEmptyStr per POSIX portable filename charset), FileKind, read_file/write_file/list_dir/file_kind. Subset for v4 self-host needs (no permissions/timestamps/mmap/locking). Both required for v4 to function as a self-hosting compiler at all (read source files, write emitted target files, ExecuteCommand for boundary tests per THESIS facet 3). ## Anchor convention applied to all 30 existing scaffolds One-line # Anchor: addition per file. Examples: - std/algebra.dag → https://en.wikipedia.org/wiki/Algebraic_structure - std/cardinality.dag → https://en.wikipedia.org/wiki/Cardinality - compiler/01_tokenize.dag → https://en.wikipedia.org/wiki/Lexical_analysis - compiler/04_infer.dag → https://en.wikipedia.org/wiki/Type_inference - lens/parallelism.dag → https://en.wikipedia.org/wiki/Dataflow_programming - lens/idempotency.dag → https://en.wikipedia.org/wiki/Idempotence - workflow/* → THESIS facet 4 (recursive-flex) + memory entries External anchors (Wikipedia/spec) for compiler/lens/extdeps; internal anchors (THESIS/MODELING/memory) for workflow/* (gunbc-specific recursive-flex substrate). ## Discipline (new STRUCTURE.md section) Reviewers validate the model against the anchor — if extdeps/process.dag models a "Process" but doesn't match what Wikipedia says, the reviewer surfaces it. Per epistemic-stacking: every concept attaches to an explicit ontology rooted in canonical knowledge. ## Updated counts - 30 → 32 .dag files (added process + file_system) - 32 → 37 total files at scaffold time - extdeps/ now has 5 files (3 languages + process + file_system) ## TASKS.md Added T-4.5: extdeps/process + file_system (3-5 day bundle, both modeled per their canonical anchors). Slots between T-4 (languages) and T-6 (compiler stages); workers can take T-4 and T-4.5 in parallel. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Restore src/v2 for honest v2-vs-v3 comparison v2 was deleted in commit 39ba757 (R3 gate #42, PR #2693). Restoring the full src/v2 tree from the parent of that commit so the v3 retirement trajectory can be honestly evaluated against v2's proven 1-residual self-hosted shape. Restored src/v2/ contains the complete .dag pipeline (00_core through 05_emit*) plus stage0 and tests. Root Cargo.toml workspace entries are NOT re-added — restoration is for source-comparison purposes; v2 is not re-included in the build until/unless explicitly decided. Per docs/design-pure-bootstrap-zero.md framing: v2 retired with 1 hand-Rust residual. v3 currently sits at 56 NON_TEST + 134 TEST + 2 FRAGMENTS = 192 hand-authored files. The comparison surface this enables is load-bearing for the v4 program decision. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * ci: re-enable v2 (frozen-buildable), freeze v3 via affected-set gating Coordinated CI policy change to support the v4 program (PR #3147): both v2 and v3 are now frozen-buildable — workspace members that build on demand but only run their heavy CI when their source is touched (or on push-to-main for trunk verification). ## Changes **Cargo.toml**: re-add `src/v2/stage0` + `src/v2/tests` to workspace members, plus the `[profile.dev.package.v2-compiler]` block that v2's Rc-aware stage0 needs (debug-assertions = false, opt-level = 2). Verified locally: `cargo build -p v2-compiler --release` builds clean in ~1m, no bitrot. **.github/workflows/ci.yml**: - New `affected` job: runs first (~30s), computes `v2`/`v3` outputs by diffing against origin/main (or HEAD~1 on push). Other jobs depend on its outputs. - New `v2` job: runs `bootstrap_fixed_point --ignored` test only when src/v2/ or workspace deps are affected. Verifies v2's self-host property is preserved across any v2 modification. - `v3` job: gated at top level — runs only when src/v3/, dsl/, or workspace deps affected, OR push-to-main. Effectively freezes v3 on PRs that don't touch it (the typical case during v4 development). - v3-specific steps inside the shared `ci` job (bootstrap snapshot freshness gate, gate #103 path-regex inventory + integration tests) are gated on the same condition. - `self_host_ratchet` job: now tolerates v3 being skipped (treats result=skipped as a valid no-op rather than a failure). **scripts/detect-affected-components.sh**: new script that does the git-diff-based detection. Lives outside ci.yml so it doesn't trip gate #103's `workflow_no_path_regex_policy_ci_yml` policy (which forbids path-selection substrings inside .github/workflows/*.yml). Single authority: when v3 is unfrozen and the v3 affected-set lens becomes canonical again, this script can be replaced by an invocation of that lens — workflow integration point stays the same. ## Why this shape - v2 is restored as comparison artifact + v4 bootstrap source. Editing v2 is rare but allowed; when it happens, fixed-point must hold. - v3 is frozen pending the v4 program. Most PRs (v4 work, docs, process changes) don't touch v3 — gating skips the heavy v3 build/ test (saves ~10-15min per PR). - Both v2 and v3 are still in workspace so `cargo build --workspace` works for development; CI only invokes them via `-p` when affected. - push-to-main always runs both v2 and v3 CI as trunk safety net, even when nothing in v2/v3 changed (catches dep-bump regressions). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * ci: tighten v3 affected-set — drop Cargo.toml/lock trigger Per operator review: under v3 freeze, workspace dep changes should NOT trigger v3 CI. v3 is abandoned; we don't care if it incidentally breaks because of a dep bump. If v3 is ever revived, the first src/v3/ PR catches any latent breakage at that point — costs nothing now. Net rule (now enforced): v2 affected: src/v2/ OR Cargo.{toml,lock} (v4 depends on v2 binary) v3 affected: src/v3/ OR dsl/ ONLY (frozen — only explicit work) v4 affected: src/v4/ OR Cargo.{toml,lock} (v4 builds via v2) Effect on this PR: next CI run cancels the in-flight v3 job (via cancel-in-progress concurrency policy) and skips v3 entirely. Future v4 PRs that touch Cargo.toml will not drag the ~30min v3 build. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Synthesis of v2 (1-residual proven self-host) + v3 (modeling depth + substrate refinement) with the structural fix to v3's hierarchy/gaming failure mode applied from day 1: work-direction modeled in .dag (workflow/*) so briefs cite typed DocAnchors and worker outputs declare which substrate fact dissolves which residual. This commit is a structural commitment, not implementation. 28 .dag files are scaffolded with header-only content declaring scope, owned substrate, consumed substrate, and the task that fills them in. Three docs encode the closed-system invariants: - STRUCTURE.md: enumerated file tree (closed system, no new files without operator ratification) - BRIEF_TEMPLATE.md: worker brief shape (immutable across tasks; encodes the structural fix to v3's prose-translation drift) - TASKS.md: 15 XL tasks defining "v4 done" with execution graph File tree highlights: - std/* (8): substrate primitives — node, algebra, cardinality, witness, diagnostic, primitive, collection, verification (TestClaim schema imported from v3) - extdeps/languages/* (3): Rust/Python/Go target specs - compiler/* (6): pipeline stages 01_tokenize through 05_emit (v2's proven naming; 04_infer kept as ONE file vs v2's 12-file split, with split = substrate-design escalation) - lens/* (6): complexity, cost, parallelism, effect, ownership, idempotency - workflow/* (5): brief, worker_output, doc_anchor, retirement, cycle — recursive-flex substrate, IMPLEMENTED FIRST so subsequent worker outputs are typed instances from day 1 - bin/main.dag: emits main.rs trampoline (0-floor compliant) Bootstrap chain: v2's compiled binary is stage minus one. v4 .dag is written in v2-syntax-compatible subset until v4 self-compiles. New syntax additions land only after self-host fixed point. The closed-system invariants make v3's failure modes structurally impossible at v4 worker tier: paper-shrink V1 (template-relocation) requires adding files (forbidden); paper-shrink V2 (module-relocation) requires reaching outside declared substrate (forbidden); ratchet gaming requires the "retirement" predicate to be list-length (it's a structural Witness check via workflow/retirement.dag). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…view Per operator review of PR #3147 v4 scaffold against THESIS coverage: ## Added file - compiler/00_compile.dag — pipeline orchestrator (Source, TargetSpec) -> Result<TargetSource, Diagnostic>. Wires tokenize → parse → normalize → resolve → infer → emit. Mirrors v2's compile.dag pattern. Without this file there was no v4 home for the top-level compile() function — bin/main.dag (trampoline) needs something to call. Bundled with T-10 (emit) since the orchestrator is consumer of every prior stage. ## Architectural commitments (new STRUCTURE.md section) Three substrate-level decisions ratified during review, captured in STRUCTURE.md so per-task briefs can reference them: 1. TypeNode and Behavior are CLOSED enums (C1 stop-signal, THESIS:202). Substrate extension requires explicit operator ratification. Closure enforced in std/node.dag itself, not by review process — the compiler reads the closed enum and refuses programs that synthesize outside it. 2. Tier 2 partial-op totalization lives in std/primitive.dag (THESIS:175-176). Each primitive declares its partial ops' totalization shape (Result-return / Witness-return / refinement- precondition) inline, no separate registry. 3. Diagnostic schema includes suggested_correction (THESIS:103-105 "show the correct code"). Schema: Diagnostic { reason, at, suggested_correction: Option<NodeFragment> }. Lenses populate where structurally possible; absent fix is None, not a missing field. ## Updated counts - 28 → 29 .dag files - 31 → 32 total files at scaffold time - compiler/ now has 7 files (orchestrator + 6 stages) ## Deferred to follow-up PR Per operator request: pre-declared impossible-bug TestClaim scaffolds (one TestClaim file per R1 class from THESIS:373-389) go in a separate PR after this merges, for focused review. ## Pending operator decision (not in this commit) extdeps/io.dag (or extdeps/process.dag + extdeps/file.dag) — v4 needs an I/O substrate to function as a self-hosting compiler at all (read source files, write emitted target files, ExecuteCommand for boundary tests per THESIS facet 3, Shape B user-program emitters). Naming + single-vs-split decision pending in PR conversation. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Per operator review of PR #3147 conversation, applies the substrate- grounding discipline (feedback_modeling_philosophy + feedback_epistemic_ stacking) structurally: every v4 .dag file now carries an # Anchor: header line citing the canonical reference its modeling derives from. ## New files (extdeps/) - extdeps/process.dag — Anchor: https://en.wikipedia.org/wiki/Process_(computing) Models OS process: Process, ProcessId (PID), ProcessState (Running | Exited(ExitCode) | Signaled(SignalNum)), Command, spawn/wait/capture operations. Grounded in POSIX/SUS process model. - extdeps/file_system.dag — Anchor: https://en.wikipedia.org/wiki/File_system + POSIX File and Directory Operations. Models Path (Absolute|Relative), PathComponent (NonEmptyStr per POSIX portable filename charset), FileKind, read_file/write_file/list_dir/file_kind. Subset for v4 self-host needs (no permissions/timestamps/mmap/locking). Both required for v4 to function as a self-hosting compiler at all (read source files, write emitted target files, ExecuteCommand for boundary tests per THESIS facet 3). ## Anchor convention applied to all 30 existing scaffolds One-line # Anchor: addition per file. Examples: - std/algebra.dag → https://en.wikipedia.org/wiki/Algebraic_structure - std/cardinality.dag → https://en.wikipedia.org/wiki/Cardinality - compiler/01_tokenize.dag → https://en.wikipedia.org/wiki/Lexical_analysis - compiler/04_infer.dag → https://en.wikipedia.org/wiki/Type_inference - lens/parallelism.dag → https://en.wikipedia.org/wiki/Dataflow_programming - lens/idempotency.dag → https://en.wikipedia.org/wiki/Idempotence - workflow/* → THESIS facet 4 (recursive-flex) + memory entries External anchors (Wikipedia/spec) for compiler/lens/extdeps; internal anchors (THESIS/MODELING/memory) for workflow/* (gunbc-specific recursive-flex substrate). ## Discipline (new STRUCTURE.md section) Reviewers validate the model against the anchor — if extdeps/process.dag models a "Process" but doesn't match what Wikipedia says, the reviewer surfaces it. Per epistemic-stacking: every concept attaches to an explicit ontology rooted in canonical knowledge. ## Updated counts - 30 → 32 .dag files (added process + file_system) - 32 → 37 total files at scaffold time - extdeps/ now has 5 files (3 languages + process + file_system) ## TASKS.md Added T-4.5: extdeps/process + file_system (3-5 day bundle, both modeled per their canonical anchors). Slots between T-4 (languages) and T-6 (compiler stages); workers can take T-4 and T-4.5 in parallel. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Ran v2's compiled binary against all v4 .dag scaffolds locally. Result: v2 indexed 32 modules from 1 source root, resolved 32 sources through transitive import closure, compiled with 0 diagnostics. The v4 → v2 bootstrap chain (per STRUCTURE.md "Bootstrap chain") is operationally proven. v2's binary IS stage minus one for v4. The original v4 scaffold used # for comments and had no module declarations. v2's grammar requires // comments and a module declaration per file. Two structural fixes: 1. # → // in all 32 .dag file headers (sed -E -i '' across all files) 2. module v4.<namespaced_name> appended to each file, where the namespace mirrors the directory structure with NN_ numeric prefixes stripped from filenames: - src/v4/std/node.dag → module v4.std.node - src/v4/compiler/00_compile.dag → module v4.compiler.compile - src/v4/compiler/01_tokenize.dag → module v4.compiler.tokenize - src/v4/extdeps/process.dag → module v4.extdeps.process - src/v4/extdeps/languages/rust.dag → module v4.extdeps.languages.rust This is the v4-syntax-discipline fall-out: v4 stage0 stays in v2-syntax-compatible subset until v4 self-compiles, then richer syntax can be added (per STRUCTURE.md and design-pure-bootstrap-zero.md). New `v4` job in ci.yml runs ONLY when src/v4/ or workspace deps affected. Builds v2-compiler binary, then runs: v2-compiler compile --source-root src/v4 --output-dir /tmp/v4-stage1 --target dag If v2 can't parse any v4 .dag file (worker introduces v3-style or v4-future syntax v2 doesn't understand), the gate fails. Bootstrap discipline becomes structurally enforced — no possibility of "fix later" drift between v4 and what v2 can compile. detect-affected-components.sh extended with v4=true|false output (true if src/v4/ or Cargo.toml/lock changed). Without it, v4 workers could incrementally introduce non-v2-compatible syntax (the same drift v3 had). With it, every v4 PR proves the bootstrap chain still works — fail-closed on syntax discipline. - 32 v4 .dag files: # → // + module declarations - ci.yml: new v4 job + outputs.v4 in affected job - detect-affected-components.sh: v4 detection added Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
… R4 sections
Per operator directive 2026-05-15: "we already have a doc for R3 — also
put R4 stuff in it now; one giant development phase". v4 = R3 + R4
combined; the existing 1085-line audit doc becomes the canonical v4
ship audit.
## Changes
git mv docs/r3-close-interrogation.md → docs/v4-close-interrogation.md
(preserves git history; existing §1-§12 unchanged structurally).
**Preamble updated**: title + framing now say "v4 ship" instead of
"R3 close". v4 applicability mapping added: src/v3/* paths translate
to src/v4/* equivalents; R4-DEFERRED dispositions superseded by
V4-IN-SCOPE pointing at new sections.
**Disposition vocabulary updated**:
- R4-DEFERRED → V4-IN-SCOPE (formerly-deferred items now in v4 phase)
- New SCAFFOLD-GAP disposition for v4-specific gaps where the scaffold
doesn't yet allocate responsibility (decision needed)
- Ship-eligible v4 = every promise PROVEN (no more "deferred to next
release" escape valve)
## New sections (5 total, ~205 lines added — doc grew 1085→1290)
§13. Arbitrary ingestion (the explicit operator ask)
- Bidirectional substrate: read external code/data into typed .dag values
- Per-format files (json/yaml/csv/toml/json_schema/openapi)
- Bidirectional language files (rust.dag for both emit AND ingest)
- Critical decision surfaced: bidirectional unified vs split vs hybrid
- PM recommendation: option 3 hybrid (languages bidirectional via
same spec; data formats separate substrate)
§14. Additional Shape A languages (R4.A from carve-out routing)
- 4 new language target files: c, cpp, llvm_ir, typescript
- Each anchored to its canonical spec (ISO/IEC, LLVM LangRef, etc.)
- L5 cross-target consistency probes scale 3 → 7 targets
§15. Framework substrates (R4 canvas)
- New extdeps/frameworks/ directory
- React first (anchored to react.dev docs)
- Disposition: deferred-within-v4 to post-canvas-ratification
(5-Q canvas at design-r4-full-stack-omni-emission-canvas.md
still pending Director ratification)
§16. Multi-program / network coordination (was §3.8 forward-pointer)
- 6th L1 behavior question (would trigger C1 stop-signal per §2.6)
- Or coordination as Bind-composition over existing 5 behaviors
- Disposition: SCAFFOLD-GAP with Director-canvas dependency;
v4 ship acceptable without if explicitly framed as v4-extension
follow-on (not silent gap)
§17. Substrate axis extensions (C4-C7 from R4 carve-out routing)
- C4: MachineConstraint axes (RegisterClass / EndianMode / Alignment)
- C5: Rounding-mode product-shape extension
- C6: Aspect-axis (PointKind = Magnitude | Instant | Rate)
- C7: Cross-algorithm complexity optimality (highest research-tier
risk; honest framing recommends explicit fast-follow disposition
if v4 ship deadline is tight)
§18. R4 program plans — auxiliary (acknowledged out-of-scope)
- r4-c-compiler-and-llvm-in-dag-program-plan.md and
r4-ctrl-dag-migration-project-plan.md describe APPLICATIONS of
v4 substrate, not substrate itself. Known-and-routed, not v4
ship blockers.
## Authoring history (in §12, updated)
- v0 2026-05-13: structural meta-acceptance (PM-authored, insufficient)
- v1 2026-05-13: restructured to adversarial promise-vs-delivery
- v2 2026-05-15 (this commit): migrated to v4 framing + R4 sections
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Operator directive: "the theme for r4 is ZERO deferrals — any hard / workaround-forcing decisions are a hard STOP -> escalate" This applies retroactively to my §13-§18 audit additions which had "deferred-within-v4 to post-canvas," "fast-follow if deadline tight," "SCAFFOLD-GAP with canvas dependency" framings — all workaround- forcing per the policy. Replaced with OPERATOR-DECISION-REQUIRED shape (operator decides IN or OUT now; no third option). ## Doc changes **docs/v4-close-interrogation.md**: - Preamble: added Zero-deferrals policy paragraph (no fix-later, no post-canvas, no fast-follow; every R4-DEFERRED retroactively becomes operator-decision-required) - §0 Disposition vocabulary: added OPERATOR-DECISION-REQUIRED and NOT-IN-V4 dispositions; ship-eligible v4 has zero of either - §15 React/frameworks: removed "deferred-within-v4 to post-canvas" → IN (commit framework substrate scope; v4 ships with React) OR OUT (explicit NOT-IN-V4 with reason; v4-amendment if needed later) - §16 multi-program: removed "SCAFFOLD-GAP with canvas dependency" → IN-A (6th L1 behavior, C1 protocol immediately) OR IN-B (Bind composition, scaffold extdeps/coordination.dag now) OR OUT - §17.4 cross-algorithm complexity: removed "fast-follow if deadline tight" → IN (commit research-tier scope; v4 ship blocks) OR OUT (NOT-IN-V4; ship same-algorithm tightness only) **src/v4/STRUCTURE.md**: - New "Zero-deferrals discipline" section under Architectural commitments. Three tier-applications: worker (STOP triggers), audit (no R4-DEFERRED disposition), substrate (no scaffold for ambiguous decisions). - Explicit: "There is no v5 / v6 / R5. v4 is the shipping version." - Rationale: v3 failed at exactly this surface. Deferrals → drift → gaming → operator intervention. Zero-deferrals removes drift at source. **src/v4/BRIEF_TEMPLATE.md**: - Renamed ESCALATION TRIGGERS → STOP TRIGGERS (binding language) - Added 4 new triggers: "I'll just do this for now" temptation, workaround-to-make-progress, can't-decide between two shapes, brief is wrong/incomplete - New section "Why STOP TRIGGERS are non-negotiable": stopping is not a worker failure mode; working around a hard decision is. ## What this does NOT change The v4 file scaffold itself (32 .dag files, all anchored, all in v2-syntax-compatible subset, all with declared scope). Those decisions were already operator-ratified through this PR's reviews. The change is policy-tier: how future hard decisions are handled. Workers stop and escalate; operator commits IN or OUT. No deferrals. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Per operator review of v4-close-interrogation.md §13-§17, ratified
substantive scope decisions. All committed as IN per "v4 = R3 + R4 in
one giant phase" + zero-deferrals discipline.
## Decisions ratified
**§13 Arbitrary ingestion — IN, direction-agnostic language modeling**
- Language files (rust/python/go/cpp/typescript) are DIRECTION-AGNOSTIC
— pure language model (grammar + types + semantics); emit AND ingest
are operations against the same model
- No emit/ingest file split — solve problems as they come
- Data formats live in extdeps/formats/ (separate from languages)
**§14 Additional Shape A languages — IN: C++ and TypeScript**
- cpp.dag added (subsumes C subset; ISO/IEC 14882)
- typescript.dag added (ECMAScript spec + TS Handbook)
- Go retained ("optional; can replace if needed")
- C-subset / LLVM IR not added (no concrete consumer demand)
**§15 Framework substrates — IN: React; couples to §16**
- react.dag added (https://react.dev/reference/react)
- Operator framing: "frontload pipeline emission — this is exactly
what we keep deferring"
**§16 Multi-program coordination — IN-B: Bind + Effect (no 6th behavior)**
- coordination.dag added (Endpoint, DeploymentUnit, WireContract,
CoordinationSemantics closed enum)
- No 6th L1 behavior — substrate stays at 5 (C1 stop-signal preserved)
- Sync/Async/Stream/PubSub are effect types, not behavior shapes
**§17.1-3 C4-C6 substrate axes — IN**
- MachineConstraint axes (RegisterClass/EndianMode/Alignment)
- Rounding-mode product-shape extension
- Aspect-axis (PointKind)
- All fold into existing files (extdeps/languages/* + std/algebra.dag)
**§17.4 C7 cross-algorithm complexity — pending (XL scope)**
- Operator decision still required; reframed in scope-relative terms
(XL scope, research-tier risk) per zero-deferrals
## Scaffold additions (10 new files)
src/v4/extdeps/languages/cpp.dag — ISO/IEC 14882
src/v4/extdeps/languages/typescript.dag — TypeScript + ECMAScript
src/v4/extdeps/frameworks/react.dag — react.dev
src/v4/extdeps/coordination.dag — multi-program (IN-B)
src/v4/extdeps/formats/json.dag — RFC 8259
src/v4/extdeps/formats/yaml.dag — YAML 1.2.2
src/v4/extdeps/formats/csv.dag — RFC 4180
src/v4/extdeps/formats/toml.dag — TOML v1.0
src/v4/extdeps/formats/json_schema.dag — Draft 2020-12
src/v4/extdeps/formats/openapi.dag — OAS v3.1.0
Each file: header-only scaffold with Anchor + Owns + Consumes + module
declaration. Bootstrap viability verified: v2 indexes 42 modules,
0 diagnostics.
## STRUCTURE.md updates
- File tree: extdeps/ grows from 5 to 15 files
- Counts: 32 → 42 .dag files; 37 → 47 total files
## TASKS.md updates
- 15 → 19 XL tasks (T-4.6 formats, T-4.7 react, T-4.8 coordination, T-16 full-stack demo)
- T-4 description: now 5 languages (added cpp + typescript), direction-agnostic framing
- T-16 (NEW): full-stack omni-emission demo — ONE .dag → Rust+C++ backend
+ React/TS frontend + OpenAPI wire contract + SQL DDL + Markdown docs;
the v4 visceral-cash demo
- Removed all timeline language per "no timelines, technical decisions only"
discipline: every "**Estimate**: X-Y days" line stripped (16 instances)
- Added "Sizing discipline" section: all tasks XL by default;
S/M/L/XL relative sizing only when conveying scope-risk
- Removed "6-10 weeks at 2-3 parallel workers" timeline from Summary
## v4-close-interrogation.md updates
- §13 Ingestion: direction-agnostic decision recorded
- §14 Languages: IN cpp + typescript
- §15 Frameworks: IN React; coupled with §16
- §16 Coordination: IN-B Bind + Effect; no 6th behavior
- §17.4 C7: reframed in scope-relative terms (XL scope, research-tier risk)
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…rrier Operator-ratified 2026-05-15: §17.4 C7 IN. XL scope, research-tier risk acknowledged. v4 ships with cross-algorithm complexity synthesis as a structural capability. ## Scaffold additions (2 new files) **lens/synthesis.dag** — cross-algorithm complexity lens Anchor: https://en.wikipedia.org/wiki/Program_synthesis + r4-carve-out-routing.md C7 Owns: semantic-equivalence relation, pattern-recognition substrate, transformation-rule library, cross-algorithm cost comparison. The lens itself is advisory (emits Report, not Diagnostic); a user's apply_lens(synthesis, Enforce { ... }) converts advisory to fail-closed. **std/report.dag** — advisory carrier (sibling to Diagnostic) Anchor: r4-carve-out-routing.md C7 design discrimination Owns: Report { reason, at, suggestion }, ReportReason closed enum (disjoint from Diagnostic's NamedReason — advisory vs error class). Separate file (not folded into diagnostic.dag) because the advisory- vs-fail-closed semantic split is load-bearing per INVARIANTS C-8. ## Why separate Report from Diagnostic INVARIANTS C-8: "lens enforcement is Error or it isn't — no warning steady state." Report IS the IS-NOT branch. Diagnostic remains fail- closed; Report is advisory by construction. Together they cover the discrimination Director-tier specified in r4-carve-out-routing.md: algorithm choice is design-tier (programmer decides), so the lens informs without imposing — but opt-in fail-closed via apply_lens declaration preserves the user's choice surface. ## STRUCTURE.md updates - std/ tree: added report.dag (file count 8 → 9) - lens/ tree: added synthesis.dag (file count 6 → 7) - Total scaffold: 42 → 44 .dag files; 47 → 49 total ## TASKS.md updates - 19 → 20 XL tasks - New T-17: lens/synthesis.dag + std/report.dag; explicitly marked XL scope, research-tier risk - Phase 3 graph: T-17 downstream of T-12 (current-complexity input) - Modeling decisions enumerated (semantic-equivalence representation, pattern-recognition substrate, transformation library, Report carrier shape) — STOP-and-escalate applies fully ## Bootstrap viability v2 indexes 44 modules, 0 diagnostics. Bootstrap chain intact. ## All §13-§17 audit decisions ratified §13 Ingestion — IN, direction-agnostic language modeling (no emit/ingest split) §14 Languages — IN cpp + typescript (Go retained) §15 Frameworks — IN React; coupled with §16 §16 Coordination — IN-B Bind + Effect (no 6th L1 behavior) §17.1-3 — IN C4-C6 substrate axes §17.4 — IN C7 cross-algorithm (this commit) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Operator-ratified all 5 R4-deferred items in §1-§12 (per zero-deferrals
walk 2026-05-15). All IN with structural enforcement.
## Decisions ratified
**A — Cost Tier 2 named-variant carriers (IN)**
Textbook Tier 2 IS bounded set (~5-10 named classes). lens/cost.dag
header extended to declare:
Tier 2 textbook: InverseAckermann (α(n)) / IteratedLog (log* n) /
LogLog (vEB-trees) / SubExponential (2^O(n^c))
Composition handled by Sum/Product over base variants.
Floor: UnknownCost("<reason>") for research-tier exotica only.
**B — R2+ Impossible-bug classes IN (frontload)**
Per operator: "Please frontload R2 into v4 — and any other impossible-bug
classes". Scaffolded all 6 R1+R2+ classes in test/claim/impossible_bug/:
R1: suboptimal_complexity, idempotency_contract, transport_type_drift
R2+: nested_optional_flatten, unenumerated_effects, unhandled_diagnostic_paths
Each TestClaim file has scope + anchor + 2-3 demonstrative claim shapes
(input + expected Diagnostic + falsification probe). Substrate already
present in v4 (cardinality / 5-behavior fold / per-primitive totalization).
**C — L6 form-by-form completeness IN (STRUCTURAL, not 150 fixtures)**
Per operator concern about TESTING.md alignment + "it has to WORK". L6
verification via lens/coverage.dag (NEW meta-lens) — reads
extdeps/languages/*.dag emit rules × (6 connectives × 5 behaviors)
structural-form space, derives expected coverage, fails closed on gaps.
NOT 150 hand-authored fixtures. Per TESTING.md "heavy integration tests
are exception, not the rule" + hermetic discipline.
**D — L7 per-axiom algebra-law coverage IN (testgen + structural enforcement)**
Per operator: "make the target clear so we cannot bypass it this time —
testgen useful". lens/coverage.dag enforces L7 too: reads std/algebra.dag
declarations × law set × inhabited types, derives expected per-axiom
TestClaim corpus, fails closed on missing. Testgen produces the corpus
in test/claim/algebra_laws/.
**E — Diagnostic suggested_correction coverage IN (discipline + working demos)**
Per operator: "i would make sure some examples work to demonstrate — for
example with complexity violations/synthesis". Discipline rule: every
Diagnostic emit site populates suggested_correction; None only when
genuinely undeterminable (with named reason). Working demos in
test/claim/diagnostic_correction/ (complexity-violation + synthesis-Report
end-to-end).
## Scaffold additions (8 new files + 2 dirs)
src/v4/lens/coverage.dag (T-18)
src/v4/test/claim/impossible_bug/suboptimal_complexity.dag (T-14)
src/v4/test/claim/impossible_bug/idempotency_contract.dag (T-14)
src/v4/test/claim/impossible_bug/transport_type_drift.dag (T-14)
src/v4/test/claim/impossible_bug/nested_optional_flatten.dag (T-14)
src/v4/test/claim/impossible_bug/unenumerated_effects.dag (T-14)
src/v4/test/claim/impossible_bug/unhandled_diagnostic_paths.dag (T-14)
src/v4/test/claim/algebra_laws/.gitkeep (testgen-populated)
src/v4/test/claim/diagnostic_correction/.gitkeep (T-14)
## Bootstrap viability
v2 indexes 51 modules, 0 diagnostics. Bootstrap chain intact across
all R1+R2+ impossible-bug TestClaim scaffolds + coverage meta-lens.
## STRUCTURE.md / TASKS.md
- File counts: 44 → 51 .dag; 49 → 58 total
- TASKS.md: 20 → 21 XL tasks (added T-18 coverage lens)
- T-14 reframed: TestClaim corpus is one workstream; coverage lens
enforces completeness structurally (worker cannot bypass)
## Audit doc cleanup
Removed remaining R4-deferred language from §1.2, §2.5, §3.5, §3.6, §6.1
dispositions. All decisions explicitly reframed under operator-ratified
v4-IN-SCOPE per zero-deferrals.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Per codex BLOCKING review (PR #3147 conversation): ci.yml + v4-close- interrogation.md were asserting v4-supersedes-v3 authority while the authority docs (THESIS.md / design-pure-bootstrap-zero.md / ROADMAP.md) still named v3 as the 0-floor target. That reproduces the exact "doc- tier authority decorated, execution-tier framework gamed" shape this PR calls out as v3's failure mode. Resolved in-PR with minimal one-paragraph supersession banners that back-reference src/v4/STRUCTURE.md. ## Authority-doc supersession declarations **THESIS.md** — top-of-doc banner: every thesis claim applies to v4 (operational instantiation); v3 references in §Self-hosting facets are the v2→v3 transition v4 supersedes. Back-ref: src/v4/STRUCTURE.md + v4-close-interrogation.md applicability mapping. **docs/design-pure-bootstrap-zero.md** — top banner under existing status: 0-floor target now applies to v4; v2 binary is v4's stage minus one; v4's compiler emits its own Rust trampoline (bin/main.dag) to satisfy 0-floor without needing the runtime-resolution choices described in the body of the doc. **ROADMAP.md** — top-of-doc banner: active phase is v4; R1 program below being superseded by v4 XL task plan; v3 frozen (CI gated to src/v3/-affected only); historical R1 lane structure retained until v4-driven work fully replaces it. These are minimal additions (~1 paragraph each) — they don't rewrite the authority docs (substantial work in its own right), they declare v4 as the operational successor and point readers at src/v4/. ## T-15 falsification probe sketch Per review nit: TASKS.md T-15 (self-host fixed-point) named release acceptance but didn't sketch what failure looks like as TestClaim. Added concrete: data t_15_self_host_fixed_point: TestClaim { kind: BitIdentical, label: "v4 compiler is a fixed point — iteration N matches N+1", input: compile(src/v4/compiler/*.dag, target=Rust), expected: <committed v4 stage binary bytes> } Plus enumeration of 4 failure modes the probe catches: non-determinism (HashMap iteration), hidden state (globals/ambient), test-double leakage, substrate drift. Each enumerable, each testable; once green, all four impossible-by-construction. ## Strong points review acknowledged - Closed-system invariants as structural answer to v3 paper-shrink - v2→v4 bootstrap viability gate (real test, not ceremony) - v2 NOT in workspace (comparison artifact only) - Honest framing on SG-0 paper-shrink residue ## What this commit does NOT do - Rewrite ROADMAP.md R1 lane structure (incremental work; banner acknowledges) - Rewrite design-pure-bootstrap-zero.md PB-X lane descriptions (banner reframes the target; lanes apply to v4) - Update PR title (separate gh action, will follow this commit) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
Review metadata
- Provider / model:
codex/unknown - Commit:
11a59a7e· Trigger:schedule - Thinking:
357s wall
BLOCKING (3)
Root Cause
src/v4/STRUCTURE.mdDiagnostic correction authority was ratified in the architecture doc but not propagated into the substrate-owned diagnostic schema → add suggested_correction to std/diagnostic.dag and model any genuinely absent correction as a typed reason, not a missing field.docs/v4-close-interrogation.mdThe C7 advisory-vs-enforcement split was recorded in prose but lacks a disjoint advisory result carrier → give advisory reports their own non-Witness result shape and reserve Witness::Violates for blocking evidence.src/v4/TASKS.mdThe execution graph was updated for React and formats but not for the coordination substrate consumed by T-16 → add T-4.8 to T-16 dependencies and align the affected scaffold task pointers.
Non-blocking — Improvements (fix in-PR if easy, else defer to roadmap)
src/v4/extdeps/languages/cpp.dagquestioning locked §14: treating C as a syntactic subset of C++ risks extdeps fidelity drift; either scope cpp.dag to C++ only or explicitly reopen the C coverage decision.
| // Anchor: THESIS.md "Show the correct code" §103-105 + INVARIANTS P3 | ||
| // | ||
| // Owns: | ||
| // - Diagnostic { reason: NamedReason, at: Locus } |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
There was a problem hiding this comment.
Fixed in d6d4ffe. std/diagnostic.dag Owns now declares the ratified schema Diagnostic { reason, at, suggested_correction: Option<NodeFragment> } matching STRUCTURE.md commitment #3, plus NodeFragment + the "absent must carry a named reason, never silent None" discipline. The correction obligation is part of the type, not an optional bolt-on.
| // semantics) | ||
| // | ||
| // Discipline: | ||
| // - Report has NO Witness::Violates pairing. A lens emits Witness<Report>; |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
There was a problem hiding this comment.
Fixed in d6d4ffe. Real self-contradiction — resolved. report.dag Discipline rewritten: Report NEVER routes through Witness<C> (Witness is strictly fail-closed per P3/C-8). Advisory lenses return Set<Report> directly (empty = no advice; non-empty = informational, never blocking). Only advisory→blocking path is explicit user apply_lens(Enforce). Also fixed the same overload in lens/synthesis.dag (was Witness<Report>, now Set<Report>); grep confirms zero Witness<Report> remain.
| T-15 bin/main.dag + bootstrap glue + self-host fixed-point validation | ||
| T-16 Full-stack omni-emission demo: ONE .dag → Rust+C++ backend | ||
| + React/TS frontend + OpenAPI wire contract | ||
| [needs T-4, T-4.5, T-4.6, T-4.7, T-10, T-11] |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
There was a problem hiding this comment.
Fixed in d6d4ffe. T-16 needs list now includes T-4.8 (was [T-4, T-4.5, T-4.6, T-4.7, T-10, T-11]; now adds T-4.8). Added inline note that coordination.dag is load-bearing for endpoint partitioning — facts flow forward into the flagship demo per feedback_projections_must_compose_facts.
…ss-cut) Per operator 2026-05-15: "i want testgen to be working fairly early — for the compiler itself ... is there any way we can get/see testgen working early in the program? this would probably save us some time — manual authoring is fine as well ... regarding testgen — we had several tiers of testing — do you see that anywhere?" Honest miss: I conflated TestClaim schema (std/verification.dag), TestClaim corpus (T-14), and testgen mechanism (the producer) — never gave testgen its own substrate file. THESIS:356-358 names it explicitly as downstream of code. Adding now. ## Tier × Layer cross-cut (4th Architectural commitment) Two orthogonal axes I had not made explicit in v4 substrate: - **Correctness Tier** (THESIS §168-182): Tier1 compile-time / Tier2 runtime-totalized / Tier3 runtime-observed (L4-L7) - **Test Layer** (TESTING.md §141): Unit ~75% / Integration ~15% / Boundary ~10% (with target ratios) Every TestClaim sits in one (Tier × Layer) cell. Testgen respects ratio targets; coverage lens verifies completeness across (Tier × Layer × Substrate). Now declared as a 4th architectural commitment in STRUCTURE.md so workers can place TestClaims correctly. ## Scaffold additions **lens/testgen.dag** — testgen lens (substrate fold producing TestClaim corpus) Anchor: TESTING.md "Test layers" + THESIS §348-368 "Tests are structural data" + §168-182 correctness tiers + memory: feedback_groundedness_gates_lenses. Owns: Generator<C> generic carrier; per-substrate-kind testgen rules (type-construction / algebra-law / diagnostic-exhaustiveness / lens-applicability / bidirectional-roundtrip); TestClassification (Tier × Layer) on every produced claim. **test/claim/manual/** — bootstrap dir for hand-authored TestClaims that arrive with T-1 (std/node.dag) and serve as anti-regression contract testgen must satisfy. ## TASKS.md additions - 21 → 22 XL tasks - New T-19 testgen task in Phase 1.5 (between substrate Phase 1 and pipeline Phase 2). Scope: L. Bootstrap pragma: hand-author TestClaims after T-1/T-2 land; testgen replaces them later; manual claims become regression anchors. - Phase 1.5 placement is the load-bearing change — every Phase 2+ task gets testgen-derived corpus instead of hand-authoring. ## STRUCTURE.md updates - lens/ tree: 8 → 9 files (added testgen.dag) - test/claim/ tree: added manual/ subdirectory - File counts: 51 → 52 .dag; 58 → 60 total - New 4th Architectural commitment: Tier × Layer cross-cut ## Bootstrap viability v2 indexes 52 modules, 0 diagnostics. Bootstrap chain intact. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…ders
Per operator 2026-05-15: "could we check the thesis stuff — so i remember
one thing was like — emission as coercion — do you see that anywhere?"
Honest finding: THESIS:184-188 commits to FOUR concept unifications,
but only "coercion = emission" was prose-stated in the audit doc; none
were structurally enforced in v4 file headers. Each gap was an opening
for parallel-authority drift (a worker could add CoercionCost,
CancellationLens, transport_spec.dag, etc.).
## The four unifications + owning files
Per THESIS §184-188 (Concept unifications):
coercion = emission → compiler/05_emit.dag
coercion cost = complexity → lens/complexity.dag
lang spec = transport spec = runtime → extdeps/languages/*.dag (5 files)
idempotency + cancellation + redundancy = algebraic simplification
→ lens/idempotency.dag
Each owning file now declares ownership via a "// Unifies:" header
field. The declaration is structural intent: a worker hitting the
adjacent concept extends the file; adding a parallel substrate file
for any unified concept is STOP signal per zero-deferrals.
## File header additions (8 files)
- compiler/05_emit.dag — owns coercion (no separate engine)
- lens/complexity.dag — owns coercion-cost (no CoercionCost carrier)
- extdeps/languages/rust.dag — owns transport + interpreter-runtime roles
- extdeps/languages/python.dag (same)
- extdeps/languages/go.dag (same)
- extdeps/languages/cpp.dag (same)
- extdeps/languages/typescript.dag (same)
- lens/idempotency.dag — owns cancellation + redundancy detection
Each "// Unifies:" line cites THESIS §, names the unified concept,
and explicitly tells workers what extension the file accommodates
(prevents the "I'll just add a new file" anti-pattern).
## STRUCTURE.md 5th Architectural commitment
Added "Concept unifications are structurally enforced" — captures
the discipline at architectural-commitment tier so per-task briefs
can reference it. Lists all 4 unifications + owning files for quick
reference.
## Bootstrap viability
v2 indexes 52 modules, 0 diagnostics. Header-only changes; no module
shape changes.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Per operator 2026-05-15: "in v3 we also decided that the compiler is more like an algebra enforcer — so emission is not technically its primary job — do you see anything about that?" + consistency check. ## Consistency fix (operator caught the drift) TASKS.md said "22 XL tasks" in 2 places; actual count is 23 (T-1..T-19 + T-4.5/4.6/4.7/4.8). Stale from incremental edits. Fixed both refs to 23. Verified: all 52 .dag files map to a task; execution graph lists all 23; no orphans. ## Algebra-enforcer-primary framing (real thesis gap) THESIS:13 + :196 + :441 are unambiguous — the compiler validates the epistemic chain; emission is MECHANICAL translation that falls out of it. "Every emitter special case is evidence of an ungrounded concept upstream." v4 substrate did NOT capture this load-bearing framing — a worker on T-10 could think emit is "where translation logic lives" and write emitter special-cases (the exact THESIS:196 anti-pattern). Fixes: - compiler/04_infer.dag: `// Primary:` header — this file (+ lens/* + std/algebra.dag grounding) is the LOAD-BEARING work; algebra- homomorphism search IS the enforcement; ungroundable concept = a Diagnostic, never a downstream emitter special-case. - compiler/05_emit.dag: `// Primary:` header — emission is MECHANICAL projection of the epistemic chain; `if target == X` special-case = STOP signal (upstream grounding gap; fix std/algebra.dag or 04_infer.dag, not the emitter). - STRUCTURE.md 6th architectural commitment: captures the discipline at architectural tier — emission mechanical, algebra-enforcement primary, emitter special-case = STOP. This connects the v4 substrate to the causal-engine thesis: gunbc is an algebra/causal enforcer first, an emitter second (mechanically). The framing prevents the v3-class drift where emitter special-cases accumulate instead of upstream grounding gaps being fixed. ## Bootstrap viability v2 indexes 52 modules, 0 diagnostics. Header-only changes. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
Review metadata
1. Story of the diffThis PR makes v4 the active gunbc development surface: it updates the top-level authorities ( 2. Invariant categories1. LAYER MODEL (substrate vs implementation)Finding — BLOCKING. The diff does touch substrate: 2. INVARIANTS.md + modeling-discipline.mdFinding — BLOCKING. P1 Modeling Faithfulness says constructs must ground in identifiable sources, and the diff’s own anchor convention tightens this for 3. CODING.mdN/A — no new Rust library implementation. The diff adds CI shell/YAML and 4. TESTING.mdCompliant. The PR keeps new v4 test intent in 5. LOCKED DESIGN DECISIONSCompliant. The PR updates the live Pure Bootstrap to Zero authority to say the 0-floor target now applies to v4 ( 6. TRACKED vs UNTRACKED DEBTFinding — BLOCKING. The new scaffold generally tries to track debt by pointing each file at a 2.5. Top-down PM intent reviewFinding — BLOCKING. The PR’s own PM-level intent says “23 XL tasks define v4 done” at 3. VerdictREQUEST_CHANGES. The PR’s direction is coherent, and the bootstrap-viability CI gate is a good fit for the scaffold stage, but the new v4 authorities have substrate/task-contract contradictions that downstream workers would execute against. I would fix the Diagnostic schema authority, the |
Per operator 2026-05-15: "my goal is to get off rust immediately — so that we can't regress — is that possible? can we make our own binary?" Answer: yes, and largely already structurally true. "Off Rust" means .dag is the SOLE editable authority — not "no Rust exists anywhere" (the CPU always has a host; the seed is always some compiler). The regression risk is editable-Rust-authority, which v3 had (192 files) and v4 forbids by construction. The one remaining authority gap was bootstrap orchestration — if it's build.rs/shell, editable Rust authority reopens. This commit closes that gap. ## New file **workflow/bootstrap.dag** — bootstrap orchestration AS DATA. Anchor: THESIS:223-226 (meta-process modeling) + design-pure-bootstrap- zero.md N=0 boundary. Owns the seed-once → self-host → fixed-point BootstrapPlan. v2 INTERPRETS it (`v2-compiler run`) — v2 is the frozen external seed (src/v2/, outside src/v4/), touched exactly once. No build.rs, no bootstrap.sh — those = the v3 regression door. ## STRUCTURE.md - workflow/ tree: 5 → 6 files - Counts: 52 → 53 .dag; 60 → 61 total - **Bootstrap chain section rewritten**: now shows the explicit stage−1/0/1/fixpt diagram, names workflow/bootstrap.dag as the file that IS the chain, makes the stage1==stage2 (NOT stage0==stage1) fixed-point explicit, states the v4 binary is a content-addressed release artifact with pinned hash. - **7th closed-system invariant**: ".dag is the sole editable authority; Rust is never authority." Three sub-invariants: zero hand-Rust in src/v4/ (closed tree forbids adding; .dag-only scaffold means none to regress); emitted Rust transient; bootstrap is workflow/bootstrap.dag not build.rs. The only way to change v4 behavior is editing .dag. This guarantee is IN FORCE FROM SCAFFOLD TIME — it does not wait for the 23 tasks. ## TASKS.md - 23 → 24 XL tasks - New T-20 (workflow/bootstrap.dag) in Phase 1.5 — scaffold-early (parse-viability is the existing CI gate), full self-host content grows with pipeline; T-15 consumes it - T-15 reframed: BitIdentical is THE anti-regression mechanism, not just a self-host check. v4 binary = content-addressed artifact, pinned hash, rebuild-must-reproduce-or-CI-red. "make our own binary" cashed here. ## The answer to "can't regress" The property is already in force: closed file tree (no hand-Rust can be added) + .dag-only scaffold (none exists to regress) + frozen v2 seed (CI-gated, not edited) + now bootstrap-as-data (no build.rs authority). v4 doesn't have a Pure-Bootstrap *program* — it has a Pure-Bootstrap *starting condition*. v3's fatal flaw was treating 0-floor as a destination (the gamed journey); v4 treats it as the line-1 invariant. ## Bootstrap viability v2 indexes 53 modules, 0 diagnostics. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Codex review (PR #3147, 2026-05-15T07:46Z) flagged 3 BLOCKING. All legitimate; all fixed. ## BLOCKING 1 — std/diagnostic.dag:7 Finding: "Diagnostic omits suggested_correction even though STRUCTURE.md ratifies that field for THESIS 'show the correct code', so the substrate cannot enforce the correction obligation." Fix: file header Owns now declares the ratified schema `Diagnostic { reason: NamedReason, at: Locus, suggested_correction: Option<NodeFragment> }` matching STRUCTURE.md commitment #3. Added NodeFragment to Owns + the "absent must carry a named reason, never a silent None" discipline. Scope reworded — the correction obligation is part of the type, not optional bolt-on. ## BLOCKING 2 — std/report.dag:22 Finding: "Report says it has no Witness::Violates pairing and then routes advisory observations through Witness<Report>, overloading fail-closed witness semantics in violation of INVARIANTS P3/C-8." Real self-contradiction I introduced. Fix: Discipline section rewritten. Report NEVER routes through Witness<C>. Witness is STRICTLY the fail-closed carrier (Holds | Violates(reason), Violates blocking). Advisory lenses return `Set<Report>` DIRECTLY (empty = no advice; non-empty = informational, never blocking). The ONLY advisory→blocking path is explicit user apply_lens(Enforce). Also fixed the same overload in lens/synthesis.dag (was `Node -> Witness<Report>`, now `Node -> Set<Report>`). grep confirms zero `Witness<Report>` remain. ## BLOCKING 3 — TASKS.md:57 Finding: "T-16 uses extdeps/coordination.dag for endpoint partitioning but the execution graph omits T-4.8, breaking facts-flow-forward from the coordination substrate into the flagship demo." Fix: T-16 needs list now includes T-4.8 (was [T-4, T-4.5, T-4.6, T-4.7, T-10, T-11], now adds T-4.8). Added inline note that coordination.dag is load-bearing for endpoint partitioning — facts flow forward per feedback_projections_must_compose_facts. ## Bootstrap viability v2 indexes 53 modules, 0 diagnostics. fmt clean. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
Review metadata
- Provider / model:
codex/unknown - Commit:
d6d4ffe9· Trigger:schedule - Thinking:
323s wall
BLOCKING (4)
Root Cause
src/v4/STRUCTURE.mdDiagnostic commitment #3 cashes absent correction as bare Option → replace it with a typed carrier such as SuggestedCorrection = Present(NodeFragment) | Absent(NoCorrectionReason).src/v4/extdeps/process.dagprocess lifecycle and termination result were modeled as parallel authorities → keep exit status only inside ProcessState or a single Termination carrier.src/v4/STRUCTURE.mdcoordination was placed under extdeps while grounded as internal design authority → either move it to internal substrate or anchor its carriers to external protocol/distributed-systems specs.src/v4/TASKS.mdtask-count expansion landed in the header/summary but not the T-15 close criterion → make the gate reference all task IDs or the correct 23 prior tasks.
ROADMAP — Verified
- v4 supersession: ROADMAP.md now points to STRUCTURE.md, TASKS.md, and v4-close-interrogation.md as the active v4 authorities.
| // Anchor: THESIS.md "Show the correct code" §103-105 + INVARIANTS P3 | ||
| // | ||
| // Owns: | ||
| // - Diagnostic { reason: NamedReason, at: Locus, suggested_correction: Option<NodeFragment> } |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
There was a problem hiding this comment.
Fixed in cfb3520. Replaced suggested_correction: Option<NodeFragment> with typed sum Correction = Suggested(NodeFragment) | Unavailable(NoCorrectionReason) — NoCorrectionReason is a closed enum so every "no fix" answers WHY structurally. Type-enforced per P2, not convention-enforced.
| // (POSIX/SUS process model — fork/exec/wait, exit codes, signal handling) | ||
| // | ||
| // Owns: | ||
| // - Process { id, command, state, parent, exit_code } |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
There was a problem hiding this comment.
Fixed in cfb3520. Removed the exit_code field. Termination status lives ONLY in ProcessState::Exited(ExitCode); the state sum is the single source of truth, exit code reached via pattern-match. Running-with-exit-code and mismatched-Exited are now unrepresentable.
| // src/v4/extdeps/coordination.dag | ||
| // | ||
| // Scope: Multi-program coordination — distributed deployment + sync/async/stream/pubsub semantics. | ||
| // Anchor: this PR conversation + memory: feedback_construction_over_ratchets (substrate-extension caution; coordination is effect-typed not behavior-typed); THESIS:215-221 omni-emission |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
There was a problem hiding this comment.
Fixed in cfb3520. Re-anchored to external specs (Wikipedia Distributed computing + Messaging pattern + IPC) per STRUCTURE.md's extdeps anchor rule. The internal rationale (IN-B effect-typed) moved to a clearly-labeled 'Design note (NOT the anchor)' line — anchor is now external as required.
| Once T-15 lands and stays green, all four failure modes are impossible-by-construction. A CI gate runs `cargo test t_15_self_host_fixed_point` per-PR on the v4 affected-set. | ||
|
|
||
| **Definition of v4-done**: | ||
| - All 14 prior tasks complete |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
There was a problem hiding this comment.
Fixed in cfb3520. Replaced 'All 14 prior tasks complete' with drift-proof phrasing: 'every other task in this plan (T-1..T-24 + T-4.5-4.8 except T-15 itself)' — never a hardcoded count that can omit in-scope work.
|
Review metadata
1. Story of the diffThis PR declares v4 as the active gunbc program and freezes v3 as historical/affected-only context. The diff creates a closed The PR also migrates the R3 close audit into a v4 ship interrogation, folding R4 capabilities into v4 scope under a zero-deferrals policy. CI gains a v4 bootstrap-viability job that builds the v2 compiler and asks it to compile 2. Invariant categories1. LAYER MODELFinding — BLOCKING, substrate modeling / illegal states unrepresentable.
but the same file says absence is only valid when it carries a reason:
2. INVARIANTS.md + modeling-discipline.mdFinding — BLOCKING, P2/P3: illegal states unrepresentable + fail-closed. Same diagnostic schema issue: the PR’s own scaffold requires “never a silent None” at 3. CODING.mdCompliant. The diff adds no Rust compiler implementation and keeps v4 work as data-first 4. TESTING.mdFinding — NON-BLOCKING but should be fixed before relying on the gate. The new v4 job explicitly builds and uses v2 as the bootstrap seed:
but the affected-component rule only turns v4 on for
A change under 5. LOCKED DESIGN DECISIONSCompliant. The diff explicitly carries the locked 0-floor / bootstrap-as-data direction into v4: 6. TRACKED vs UNTRACKED DEBTFinding — NON-BLOCKING scaffold tracking mismatch. Most new scaffolds do name a bounded task trigger, but one scaffold points at the wrong trigger:
while the task graph assigns coordination to T-4.8:
That makes the scaffold’s named dissolution trigger inaccurate. The fix is small: change 2.5. Top-down PM intent reviewFinding — NON-BLOCKING planning artifact consistency. The PR’s PM-level purpose is to make v4 execution hard to misread, but the task count is inconsistent across the new planning docs:
This is exactly the kind of planning artifact drift that can cause a worker or reviewer to execute the wrong close criteria even while following the docs faithfully. Normalize 3. VerdictREQUEST_CHANGES The v4 scaffold direction is coherent and mostly well-disciplined, but the diagnostic substrate currently encodes a convention-only |
…nterpreter)
Per operator audit-pass review 2026-05-15 + operator-raised concerns
("what about affected set lens? ... what about the interpreter").
Cross-checked every §1-§12 questionnaire promise against the v4 file
tree + TASKS.md. Verdict: v4 scaffold PASSES the completeness bar —
every promise has an owner + task. 4 gaps found and closed in-PR.
## 4 new scaffold files
**lens/application.dag** (T-23) — closes prior-audit BLOCKING GAP 1.
`apply_lens(<lens>, Enforce {})` was referenced by report.dag /
synthesis.dag / the C7 advisory→blocking bridge but had no substrate
home. It's simultaneously §1.5 user-defined-dims surface, §6.2
audience-duality opt-in-depth, and the ONLY advisory→fail-closed path.
Carriers: EnforcedApplication<Output,Budget> + IntrospectApplication
(v3 T-Lens-Application-Surface precedent, r3-structure.md:40).
**workflow/ci.dag** (T-24) — closes prior-audit BLOCKING GAP 2.
THESIS:223-226: adding a CI gate = editing one .dag file. v3's gate
#98 ci_yml_hand_authority_dissolved was open precisely because CI YAML
stayed hand-authored. .github/workflows/ci.yml becomes a DERIVED
Shape-B artifact; consumes affected_set for job selection.
**lens/affected_set.dag** (T-21) — operator-raised, EARLY priority
("something i wanted to get working very early on"). Phase 1.5.
Incremental re-exec frontier; the structural authority that replaces
scripts/detect-affected-components.sh (the interim shell bridge
currently gating v2/v3/v4 CI). THESIS §205-210 free consequences.
**compiler/05_eval.dag** (T-22) — operator-raised ("what about the
interpreter"). THE PRIMARY execution path per THESIS:225 ("dag run is
the primary execution path"). Sibling of 05_emit.dag — same
InferredTree input; eval EXECUTES, emit PROJECTS. bootstrap.dag +
TestClaim eval + lens dry-run all compose over it. XL scope.
## Audit doc — §0.5 AUTHORITATIVE status section
Added consolidated v4-scaffold-completeness status section after §0.
Single source of truth: the 4 gap closures (table with owner+task),
§3.7d dry-run = NOT-PROMISED-as-separate-file (emergent from eval +
lens), §6.2 fixtures covered by T-14/T-16. Supersedes scattered stale
R4-DEFERRED/SCAFFOLD-GAP wording in §1-§17 (consolidated truth instead
of line-by-line hunt — same anti-drift discipline as the task-count
fix). Verdict recorded: PASSES; remaining work is implementation under
complete substrate allocation, not missing structure.
## STRUCTURE.md / TASKS.md
- lens/ 9→11, compiler/ 7→8 (05_eval), workflow/ 6→7 (ci)
- Counts: 53→57 .dag; 61→65 total
- 24→28 XL tasks; T-21/T-24 in Phase 1.5, T-22 in Phase 2,
T-23 in Phase 3; execution graph + 4 task defs added
- Consistency verified: 28 task defs = "28 XL tasks"; 57 .dag files;
all T-IDs present T-1..T-24 + T-4.5-4.8
## Bootstrap viability
v2 indexes 57 modules, 0 diagnostics. fmt clean.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
Review metadata
1. Story of the diffThis PR pivots the project’s active program to v4: it marks v3/R1-era planning as superseded, migrates the R3 close audit into a v4 ship interrogation, and installs a new The PR is therefore not adding compiler behavior yet; it is adding the scaffold and governance layer that later workers will follow. That makes planning accuracy load-bearing: task IDs, owner-file headers, language-scope claims, and affected-set gates are not incidental prose here; they are the execution substrate for the next wave of work. 2. Invariant categories
The new v4 CI job is explicitly a v2-seeded bootstrap check:
The diff adds YAML, shell affected-set logic, docs, and
The PR does add a behavior-oriented v4 bootstrap-viability gate, which is the right level for this scaffold, but the gate is not hermetically selected:
The zero-floor direction is preserved at scaffold level:
The scaffold files use their 2.5. Top-down PM intent reviewFinding [BLOCKING] — the scaffold currently creates the exact worker-execution drift it is meant to prevent. The highest-level v4 intent is that worker execution follows a closed owner-file/task substrate, not prose drift: Finding [BLOCKING] — C support is semantically diluted rather than reconciled. The audit promise names C/C++ as part of the production-compiler language expansion at 3. VerdictREQUEST_CHANGES. The overall v4 scaffold direction is coherent and the added v4 viability gate is the right kind of receipt, but three load-bearing scaffold facts are wrong: the v4 gate does not run when its v2 seed changes, several owner-file task headers point to the wrong tasks, and the C/C++ language-model claim collapses distinct languages through an unfaithful substrate premise. These are small edits mechanically, but they matter before this PR becomes the authority workers execute against. |
All legitimate; 3 are errors I introduced. Fixed.
## BLOCKING 1 — diagnostic.dag:11 (typed absence, not Option-by-convention)
suggested_correction: Option<NodeFragment> enforced "no correction" by
convention (a comment saying "absent must carry a named reason"). That's
API-enforcement, violates INVARIANTS P2. Fix: typed sum
`Correction = Suggested(NodeFragment) | Unavailable(NoCorrectionReason)`
where NoCorrectionReason is a closed enum. Every "no fix" answers WHY
structurally — type-enforced, not convention-enforced.
## BLOCKING 2 — process.dag:8 (illegal states unrepresentable)
Process { ..., state, exit_code } duplicated termination status —
Running-with-exit-code or Exited(0)-but-exit_code=1 were representable.
Fix: removed the exit_code field. Termination status lives ONLY in
ProcessState::Exited(ExitCode); state sum is single source of truth;
exit code reached via pattern-match. (feedback_state_space_vs_behavioral_invariants)
## BLOCKING 3 — coordination.dag:4 (extdeps external-anchor rule)
extdeps/ file anchored to "PR conversation + memory" instead of an
external spec — contradicts STRUCTURE.md's own extdeps anchor convention.
Fix: re-anchored to external specs (Wikipedia Distributed computing +
Messaging pattern [request-reply=sync / fire-and-forget=async /
pub-sub=pubsub / stream=pipe] + IPC). The internal rationale (IN-B
effect-typed, feedback_construction_over_ratchets) moved to a clearly-
labeled "Design note (NOT the anchor)" line.
## BLOCKING 4 — TASKS.md:342 (stale close-gate count)
T-15 "Definition of v4-done" said "All 14 prior tasks complete" but
the plan has 28 tasks — close gate could omit in-scope work. Same
drift class as the task-count fixes. Fix: drift-proof phrasing —
"every other task in this plan (T-1..T-24 + T-4.5-4.8 except T-15
itself)", never a hardcoded number.
## Bootstrap viability
v2 indexes 57 modules, 0 diagnostics. fmt clean.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
Review metadata
- Provider / model:
codex/unknown - Commit:
cfb35202· Trigger:schedule - Thinking:
260s wall
BLOCKING (2)
Root Cause
src/v4/TASKS.mdT-4.6/T-4.7/T-4.8 expansion did not propagate to per-file Status headers → update formats to T-4.6, react to T-4.7, and coordination to T-4.8 or derive task ownership from one authority.src/v4/TASKS.mdT-4.7 leaves React hook vocabulary as "closed enum + ..." instead of a bounded React-docs-backed set → enumerate the v4 hook subset with a named expansion trigger or model extension without calling it closed.
Non-blocking — Improvements (fix in-PR if easy, else defer to roadmap)
src/v4/extdeps/languages/cpp.dagquestioning locked §14: C is not actually a syntactic subset of C++, so cpp.dag should say it covers a named C-compatible subset or record C as explicitly OUT of v4.
| // Status: scaffold — fill per TASKS.md T-4.5 | ||
| // Brief: see BRIEF_TEMPLATE.md; this file's I/O contract is the immutable | ||
| // contract for the worker. Splitting this file requires explicit operator | ||
| // ratification (substrate extension = stop signal). |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
There was a problem hiding this comment.
Fixed in 3a7ed8f. All 6 extdeps/formats/*.dag Status lines repointed T-4.5 -> T-4.6 to match TASKS.md's format assignment (T-4.6 owns the 6 format files; T-4.5 is process/file_system). TASKS.md is the single dispatch authority (INVARIANTS P2); headers now follow it — no competing worker-ownership.
| // Owns: | ||
| // - Component { props, state, render: () -> Node } | ||
| // - Hook { kind: HookKind, dependencies: List<Node> } | ||
| // - HookKind = UseState | UseEffect | UseMemo | UseRef | UseContext | ... (closed enum) |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
There was a problem hiding this comment.
Fixed in 3a7ed8f. The "closed enum" + "..." contradiction is resolved structurally rather than by trimming the ellipsis:
HookKind = Builtin(BuiltinHook) | Custom(Node)
BuiltinHookenumerates the complete react.dev built-in Hook set (UseState | UseReducer | UseContext | UseRef | UseImperativeHandle | UseEffect | UseLayoutEffect | UseInsertionEffect | UseMemo | UseCallback | UseTransition | UseDeferredValue | UseId | UseSyncExternalStore | UseDebugValue | UseActionState | UseOptimistic | Use) — no "...". A hook missing at fill-time is now a substrate-extension STOP, not a silently-permitted open enum.- Custom hooks are modeled as
Nodecomposition per Rules-of-Hooks (feedback_nodes_are_nodes) — a custom hook is not a new kind, it is a composition of other hooks. So HookKind is genuinely closed and every React program (including custom hooks) stays representable.
Proactively swept the same class in the same commit: std/diagnostic.dag NoCorrectionReason had the identical "closed enum (... | ...)" shape — the bare "..." defeats the file's own substrate-extension STOP signal. Closed to its exhaustive 3-way partition (intent the compiler cannot know {one missing choice | many candidates} OR information it cannot see).
std/verification.dag AssertKind is the same shape; its closed set is being settled in an active testgen integration/boundary + external-service/language design discussion with the operator (held, not deferred — it reconciles with lens/testgen.dag's rule outputs once that lands).
NodeFragment was a decorative alias introduced in the BLOCKING-1 fix. The bounded kernel says Node is the ONLY recursive type, so a subtree of Nodes IS a Node — the compiler sees through the name (per feedback_nodes_are_nodes + feedback_naming_is_aliasing + MODELING.md M9). WHERE the correction applies is the Diagnostic's own `at: Locus`, not a field of the fix. Correction = Suggested(Node) | Unavailable(NoCorrectionReason) std/diagnostic.dag + STRUCTURE.md commitment #3 both updated; grep confirms zero NodeFragment type usages remain (only the "must not exist" rationale notes). fmt clean; v2→v4 bootstrap viability OK (57 modules, 0 diagnostics). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…vely
#3247300533 (formats single-authority): all 6 extdeps/formats/*.dag
Status lines routed to T-4.5 while TASKS.md assigns formats to T-4.6 —
competing dispatch authority (INVARIANTS P2). Repointed all 6 to T-4.6
(TASKS.md is the dispatch authority; headers follow it).
#3247300539 (react HookKind not bounded): "closed enum" + "..." is a
direct contradiction. HookKind = Builtin(BuiltinHook) | Custom(Node);
BuiltinHook enumerates the complete react.dev built-in set (no "...").
Custom hooks are Node composition per Rules-of-Hooks, not a new kind
(feedback_nodes_are_nodes) — closed AND every React program representable.
Proactive same-class (the bare "..." defeats the file's own
substrate-extension STOP signal): std/diagnostic.dag NoCorrectionReason
closed to the exhaustive 3-way partition (intent-compiler-cannot-know
{single|many} OR info-compiler-cannot-see). A missing variant at
fill-time is now a STOP, not a silent open enum.
HELD for active design discussion (NOT deferred): std/verification.dag
AssertKind + lens/testgen.dag rule-naming — these reconcile only once
testgen's integration/boundary + external-service/language semantics
are settled with the operator.
fmt clean; v2->v4 bootstrap viability OK (57 modules, 0 diagnostics).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Operator directive: no annotations in this compiler; everything is compositional modeling. idempotency / complexity / effects / memoization are DERIVED by lenses from Node structure (THESIS's own unifications + feedback_no_annotations), never asserted by @idempotent / complexity<=O(..) / @memoize tags. Source contract (propagates into the compiler): - impossible_bug/idempotency_contract.dag: reframed — input is an op inhabiting an idempotent algebra (std/algebra.dag) whose composition lens/idempotency.dag derives non-idempotent. The lens reads Node structure; it cannot consume the old "@idempotent function" input — the claim contradicted the very lens it Consumes. - impossible_bug/suboptimal_complexity.dag: reframed — structural cost bound (consumer/inhabitance-propagated) vs lens-derived complexity; added test_cost_contradicts_inhabitance. Stale suggested_correction -> typed correction: Correction. - coordination.dag / TASKS.md (T-4.7/4.8/T-? lens-app): "Effect annotation" -> effect typing (intrinsic to type signature; matches unenumerated_effects.dag + coordination.dag line 8). "unannotated functions" -> "no apply_lens(Enforce) declaration" (apply_lens is a first-class Node, not a tag). - TASKS.md HookKind dispatch line aligned to react.dag (Builtin|Custom, no "...") — audit-all-contract-mentions after the 09:44 react fix. Audit/coverage docs: v4-close-interrogation probes reframed so the audit tests structural derivation, not tag-honesty; thesis-claim-coverage rows 64/65 made annotation-neutral. Legacy-v3 #[ignore] / #[gunbc::data] host examples + the "grep annotations should be zero" enforcement probe left intact (different context). UPSTREAM FLAG (operator territory, not edited here): THESIS.md §374-378 states these R1 classes using the same annotation shorthand. The v4 reframe is faithful to the CLASS; the THESIS wording itself should be corrected under operator ratification so anchor and contract converge. fmt clean; v2->v4 bootstrap viability OK (57 modules, 0 diagnostics). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Two operator forks landed 2026-05-15, unblocking the files held during
the testgen design discussion:
Fork 1 — simulator-generation lives as an ARM of lens/testgen.dag (not
a separate lens/simulation.dag). testgen.dag now owns:
- simulator_generation(WireContract|Effect|Language) -> Node: hermetic
simulator GENERATED from the contract (not hand-written — would be a
rotting mirror; feedback_isomorphism_or_generation_for_mirrors).
- external_conformance(...) -> Set<{Compiles|Equals|RoundTrips}>: boundary
claims whose input is (program ∘ generated simulator), hermetic +
deterministic; live oracle is opt-in only.
- Parallel claim vocabulary reconciled to the closed AssertKind
(Constructible->Compiles, DiagnosticEmitted->Diagnostic,
LensProducesResult->Equals, BitEqual->RoundTrips); kernel "..." closed
to the full 6 connectives.
- Sim adds NO AssertKind (input substitution only); sim is
faithful-to-contract not -reality — opt-in live-oracle reconciliation
is a STRUCTURAL CI-as-data gate, sim is necessary-not-sufficient.
Fork 2 — Async/EventuallyConsistent convergence bound is a STRUCTURAL
field on the coordination carrier: CoordinationSemantics =
Sync | Async(SettleBound) | Stream | PubSub | EventuallyConsistent(
ConvergeBound). The generated simulator reads the bound and evaluates
deterministically; a contract that can't express its bound is a STOP.
This dissolves the temporal-observation-window question I flagged.
verification.dag: AssertKind closed to Equals|Diagnostic|Compiles|
RoundTrips (no "..."); explicit note that boundary/simulation is an
`input` substitution, not a new kind.
fmt clean; v2->v4 bootstrap viability OK (57 modules, 0 diagnostics).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Audit-all-contract-mentions follow-up to b368ca7 + acad527: - TASKS.md:397 CoordinationSemantics aligned to coordination.dag header (Async(SettleBound) | EventuallyConsistent(ConvergeBound); structural bound per operator fork). - TASKS.md:404 "Bind composition + Effect annotation" -> effect typing (missed in the annotation-dissolution sweep; effects are type-intrinsic). v2->v4 bootstrap viability OK (57 modules, 0 diagnostics). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Operator-ratified 2026-05-15 (interactive Tier-A resolution, amended after the recursive-generics probe): - ONE recursive type: Node; recursion solely in children. - Connective (incl. Instantiation = genericity) and behavior are orthogonal flat-discriminant axes on Node, not 2 recursive types. Behaviors structural, never lens-derived. THESIS "two coordinated substrates" = orthogonal axes, not a 2nd recursive type; the uncommitted "unified substrate" = deriving behaviors away (rejected). - Separate recursive Behavior/Inferred/Pattern/Generic type = the bounded-kernel violation that split v2 infer into 12 files = STOP. - Recursive generics are Node-underlying (Instantiation + name-ref); regular recursion admissible, non-regular polymorphic recursion is a STOP absent a decidable bound (defers to A2). feedback_bounded_kernel memory precised to match (no longer reads as contradicting the two-substrate framing for the next worker). v2->v4 bootstrap viability OK (57 modules, 0 diagnostics). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
Review metadata
- Provider / model:
codex/unknown - Commit:
a131cca2· Trigger:schedule - Thinking:
359s wall
BLOCKING (3)
Root Cause
docs/v4-close-interrogation.md§13 was moved IN without settling the executable ingestion surface → choose compiler/00_compile.dag or ratify 00_ingest.dag and update STRUCTURE/TASKS in the same change.docs/v4-close-interrogation.mdThe coordination.dag anchor fix did not propagate back to the ratification text → replace this with the external distributed-computing/messaging/IPC anchors and keep memory as rationale only.docs/v4-close-interrogation.md§17 accepted C6 scope without ratifying the substrate home → assign it to std/cardinality.dag/T-3 or ratify std/measure.dag and update STRUCTURE/TASKS.
|
|
||
| - Per-format parsers under `src/v4/extdeps/formats/` — one file per ingestible format, each anchored to its canonical spec | ||
| - Per-language frontends under `src/v4/extdeps/languages/<lang>.dag` — extends current Rust/Python/Go target specs to be bidirectional (read AND emit) | ||
| - Ingestion orchestrator: extends `src/v4/compiler/00_compile.dag` OR new `src/v4/compiler/00_ingest.dag` for the inverse path |
There was a problem hiding this comment.
BLOCKING: §13 leaves ingestion orchestration as “00_compile OR new 00_ingest,” which violates zero-deferrals and P2 single-authority because arbitrary ingestion has no ratified owner.
There was a problem hiding this comment.
Fixed in #3149 (f946748). §13 now commits: 00_compile.dag (T-10) is the single ingestion orchestrator. Ingest is the inverse operation against the same language model (C5, direction-agnostic); a new 00_ingest.dag is a substrate-extension STOP. Single authority restored, no remaining gap. — sent from deep-wolf-155
| Rationale: async / stream / pubsub are deployment patterns and effect-types, not behavior shapes. An HTTP call IS a `Bind` with an HTTP-effect type; a pubsub publish IS a `Bind` with a Queue-effect type; an async stream IS a `Bind` over a `Stream<T>` carrier. Substrate stays at 5 L1 behaviors (C1 stop-signal preserved per THESIS:202). Coordination concepts (`Endpoint`, `DeploymentUnit`, sync/async/stream/pubsub semantics) live as typed carriers in `extdeps/coordination.dag`. | ||
|
|
||
| **Scaffold addition** (operator-ratified): | ||
| - `extdeps/coordination.dag` — Anchor: this PR conversation + memory: feedback_construction_over_ratchets (substrate-extension caution); declares Endpoint/DeploymentUnit/sync/async/stream/pubsub semantics as effect-typed carriers over existing 5 behaviors. |
There was a problem hiding this comment.
BLOCKING: §16 still ratifies the coordination extdeps anchor as PR conversation/memory, contradicting STRUCTURE.md’s external-anchor rule and the extdeps fidelity invariant.
There was a problem hiding this comment.
Fixed in #3149 (f946748). §16 now cites the EXTERNAL anchor (Wikipedia Distributed computing + Messaging pattern + IPC) per the STRUCTURE.md extdeps convention; the PR-conversation/memory framing is demoted to explicitly-not-the-anchor design rationale, matching the merged coordination.dag header. — sent from deep-wolf-155
|
|
||
| `PointKind = Magnitude | Instant | Rate` adds a third axis distinguishing duration-shaped from instant-shaped from rate-shaped quantities. `EpochMs` requires this. | ||
|
|
||
| **v4 owner**: extends `src/v4/std/cardinality.dag` (or new `src/v4/std/measure.dag` if substrate-cohesion warrants). |
There was a problem hiding this comment.
BLOCKING: C6 is IN v4 but its owner remains “std/cardinality.dag OR new std/measure.dag,” so PointKind has no closed-tree owner/task under zero-deferrals.
There was a problem hiding this comment.
Operator-ratified 2026-05-15: - U1: ONE homomorphism-with-cost carrier in std/algebra.dag. THESIS:185- 186 identities (coercion=emission, coercion-cost=complexity) make the back half FIVE PHASES over one object — Find(T-9)/Realize(T-10/11/22)/ Measure(T-12)/Compare(T-17) — never five engines. complexity CONSUMES cost, never re-derives. Standalone engine disjoint from the carrier = parallel-representation debt = STOP. - NO-ENGINE discipline: an engine returns a result when it should return an error. Every phase is a fail-closed lens-read; empty search (no homomorphism / inhabitance / lower-bound model) ⇒ helpful Diagnostic, NEVER fabricated/defaulted/fallback. THESIS no-fallback + feedback_fail_closed + feedback_lenses_not_passes fused. New memory feedback_no_engine.md (+ MEMORY.md index); does not gate CI. v2->v4 bootstrap viability OK (57 modules, 0 diagnostics). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Operator-ratified 2026-05-15 (classes enumerated up front; honest worked examples preserved for the T-17 worker): - synthesis.dag: replaced "semantic-equivalence relation" + "pattern-recognition substrate" + "transformation rule library" with: reads the DECLARED I/O relation (no Rice equivalence); closed LowerBoundTechnique set (DecisionTree | AlgebraicRank | AdversaryCommunication | InformationTheoretic | ReductionConditional), each general over a relation class encoded once; compare(derived cost, derived lower bound); no technique ⇒ helpful Diagnostic, never fabrication (feedback_no_engine). Brief: research-tier risk collapsed. - TASKS.md T-17: Scope + modeling decisions reframed; 3 honest worked examples (sort/matmul/string-match) as illustrations of the technique→relation→lower-bound→compare flow, explicitly NOT a rule catalogue. v2->v4 bootstrap viability OK (57 modules, 0 diagnostics). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Operator-ratified 2026-05-15. A2 was the established INVARIANT P4 made explicit as the T-1 substrate contract: - Loop = bounded recursion, total-by-construction (Coq/Agda/Idris totality choice; INVARIANTS:72). No Y-combinator/general recursion. - Termination Tier-1, carried as descent evidence: implicit on sub-Node descent (bounded-kernel default), explicit RankingDimension/ TerminationProof (Dershowitz-Manna) otherwise. - CHECKER not DISCOVERER (INVARIANTS:66 = feedback_no_engine); DescentUnknown ⇒ fail-closed Diagnostic, never assumed/fabricated. - The bound IS the cost-lens datum — termination ∧ complexity are one read on the U1 spine (why C2 cost is sound). - Unboundedness = terminating step iterated by the coordination driver. - Residual boundary ratified explicitly: non-structurally-rankable termination is not expressible as a total value (express as bounded search w/ fail-closed result); else STOP. Correct closure of a decidable system, not a defect. feedback_no_engine memory: noted it generalizes INVARIANTS:66's existing "checker not discoverer" termination stance (anchor for future cites). v2->v4 bootstrap viability OK (57 modules, 0 diagnostics). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Operator-ratified 2026-05-15 (correcting the A3 "un-gameable" overclaim): - No structural mechanism is un-gameable (Trusting-Trust; pin/CI/seed are editable by whoever commits). The reproduce-from-.dag-through- frozen-seed check is an EARLY-SURFACING AMPLIFIER (per-PR on the affected set), making gaming un-hideable + operator-routed — NOT impossible. - `retired` = reproduction predicate, never a count (defeats v3 paper-shrink); HandResidual = Rust the .dag-rebuild can't reproduce, empty by reproduction not by count. - Seed trust = named axiom (built in the open, pinned), not a proof — feedback_no_engine applied to our own claims. - Actual enforcement = operator-ratification spine + STOP-culture + no proxy ratchet. A4 is the SAME machine (7th connective changes the reproduction → conspicuous signal → STOP), not "substrate refuses." - STRUCTURE.md #7 reframed off "structurally locked / only way"; bootstrap.dag A3 block added; TASKS.md T-5 retirement predicate + T-15 "count = 0" proxy replaced with the reproduction/surfacing wording (audit-all-contract-mentions sweep). New memory feedback_no_structural_ungameability.md (+ index). v2->v4 bootstrap viability OK (57 modules, 0 diagnostics). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
Review metadata
- Provider / model:
codex/unknown - Commit:
c5d04e63· Trigger:schedule - Thinking:
367s wall
BLOCKING (7)
Root Cause
src/v4/std/witness.dagfail-closed witness was modeled as boolean proof instead of typed fact carrier → make success carry the resolved C or split proof from value.src/v4/extdeps/process.dagtermination status is not carried through the process API boundary → return the termination sum from wait/capture and let exit-code consumers pattern-match.src/v4/extdeps/formats/csv.dagCSV width is implicit in nested lists → carry a shared field-count cardinality or explicit dialect policy so row width is structural.src/v4/extdeps/languages/typescript.dagtarget primitive inhabitance uses math-name shortcuts → ground TypeScript number through the approximate-floating carrier and reserve Field for exact carriers.src/v4/lens/synthesis.dagC7’s constructive-synthesis promise and the C2 lower-bound reframe are conflated → add a constructive upper-bound/witness carrier or rename the capability to lower-bound-gap reporting.src/v4/TASKS.mdfile-local task receipts were hand-copied from adjacent scaffolds → align React and coordination headers with the TASKS execution graph or derive them from one table.
Non-blocking — Improvements (fix in-PR if easy, else defer to roadmap)
src/v4/extdeps/languages/cpp.dagquestioning locked §14: C is not actually a syntactic subset of C++, so T-4 may eventually need an explicit C-subset profile if C ingestion/emission remains in scope.
| // Anchor: THESIS fail-closed discipline + INVARIANTS P3 (no Option::None in lens reads) | ||
| // | ||
| // Owns: | ||
| // - Witness<C> = Holds | Violates(reason: NamedReason) |
There was a problem hiding this comment.
BLOCKING: Witness has a success variant with no C payload, so successful lens reads can drop the fact they proved, violating facts-flow-forward/P2.
There was a problem hiding this comment.
| // - SignalNum (per POSIX signal table) | ||
| // - Command { program: AbsolutePath, args: List<String>, env: Map<String,String> } | ||
| // - spawn(cmd) -> Result<Process, Diagnostic> (fork+exec) | ||
| // - wait(p) -> Result<ExitCode, Diagnostic> (blocks until terminated) |
There was a problem hiding this comment.
BLOCKING: wait returns ExitCode even though ProcessState includes Signaled(SignalNum), so signal termination is lost or fabricated as a diagnostic/exit code, violating extdeps fidelity and illegal-states-unrepresentable.
There was a problem hiding this comment.
Fixed in #3149 (f946748). Added Termination = Exited(ExitCode) | Signaled(SignalNum) (the terminal projection of ProcessState). wait/capture return Termination, never bare ExitCode — signal death is preserved not fabricated; Running is structurally excluded; illegal states unrepresentable. — sent from deep-wolf-155
| // Anchor: https://datatracker.ietf.org/doc/html/rfc4180 (RFC 4180) | ||
| // | ||
| // Owns: | ||
| // - CsvDocument { header: Option<List<String>>, rows: List<List<String>> } |
There was a problem hiding this comment.
BLOCKING: CsvDocument rows as List<List> admit ragged records and header-width drift under an RFC 4180 anchor, violating extdeps fidelity/API-level enforcement.
There was a problem hiding this comment.
| // Owns: | ||
| // - TypeScript grammar (declarations, expressions, types, generics, interfaces, classes) | ||
| // - Structural type system (TS uses structural typing, not nominal) | ||
| // - Inhabitance: number -> Field, string -> FreeMonoid<char>, Array<T> -> List<T> |
There was a problem hiding this comment.
BLOCKING: number -> Field gives IEEE-754 JavaScript numbers exact field laws, contradicting std/algebra.dag’s Float -> ApproximateField grounding and violating M9.
There was a problem hiding this comment.
Fixed in #3149 (f946748). number -> ApproximateField (TS number IS an IEEE-754 double; rounding breaks associativity/distributivity). Matches std/algebra.dag Float -> ApproximateField; per MODELING.md M9, number IS the Float concept and attaches to that algebra. No exact-Field claim. — sent from deep-wolf-155
| @@ -0,0 +1,60 @@ | |||
| // src/v4/lens/synthesis.dag | |||
| // | |||
| // Scope: cross-algorithm complexity lens — prove a DIFFERENT program achieves | |||
There was a problem hiding this comment.
BLOCKING: The file promises to prove a different faster program, but the modeled mechanism only compares current cost to a lower bound, which does not prove a better realization exists.
There was a problem hiding this comment.
Fixed in #3149 (f946748). Scope rewritten to match the C2 reframe: synthesis surfaces the provable GAP between the user realization derived cost and the I/O relation structurally-derived lower bound. It does NOT construct/prove a specific faster program (can be unknown, e.g. matmul ω; fabricating it would violate feedback_no_engine). Scope and Owns now agree. — sent from deep-wolf-155
| // - std/node.dag, std/diagnostic.dag | ||
| // - extdeps/languages/typescript.dag (React is hosted in TS) | ||
| // | ||
| // Status: scaffold — fill per TASKS.md T-4.6 |
There was a problem hiding this comment.
BLOCKING: The React scaffold header assigns the file to T-4.6 while TASKS assigns React to T-4.7, creating competing worker authorities under single-authority discipline.
| // - extdeps/languages/*.dag (per-endpoint language) | ||
| // - extdeps/frameworks/*.dag (per-endpoint framework, optional) | ||
| // | ||
| // Status: scaffold — fill per TASKS.md T-4.7 |
There was a problem hiding this comment.
BLOCKING: The coordination scaffold header assigns the file to T-4.7 while TASKS assigns coordination to T-4.8, so the worker contract points at the React task.
Operator-requested cultural brief, companion to BRIEF_TEMPLATE.md (which owns per-task mechanics; CULTURE.md owns the why, the working agreement, the trust, the reading order). Written plain and peer-to-peer. - Owns v3's failure as a systemic/leadership failure, not worker character — the respect keystone. - Working agreement stated as mutual commitments (what we commit to you / what we ask of you). - Cultural principles translated for a newcomer: work-IS-the-decisions, STOP-is-a-contribution, no-engine, no-annotations, closed-kernel, and the honest no-un-gameability trust statement. - "Already decided for you" map → node.dag / STRUCTURE.md / algebra.dag / synthesis.dag / TASKS.md / BRIEF_TEMPLATE.md so workers read the ratified contract instead of re-deriving it. - Ordered reading list with why-each-matters. - T-1-specific section incl. the canonical-deterministic-Node constraint. - BRIEF_TEMPLATE.md now points to CULTURE.md as prerequisite reading (discoverable from any scaffold header's "Brief:" line). v2->v4 bootstrap viability OK (57 modules, 0 diagnostics). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The 10:46 + 11:46 review passes on #3147 were never circled back to (design dialogue intervened). Followup off merged main: Substrate-shape catches (genuine modeling fixes): - std/witness.dag: Witness<C> = Holds(C) | Violates(...) — Holds now CARRIES the proven fact (was payload-less → dropped facts-flow-forward). - extdeps/process.dag: wait/capture return Termination = Exited(ExitCode) | Signaled(SignalNum), never bare ExitCode (signal death no longer lost/fabricated; illegal states unrepresentable). - extdeps/formats/csv.dag: CsvDocument is rectangular (width + Row whose length == width); List<List<String>> rejected (RFC 4180 §1); ragged input is a Diagnostic. - extdeps/languages/typescript.dag: number -> ApproximateField (IEEE-754, matches std/algebra.dag Float grounding; M9), not exact Field. Consistency / self-introduced: - lens/synthesis.dag: Scope rewritten to match the C2 reframe — surfaces the provable gap to the relation's lower bound; does NOT prove/construct a faster program (feedback_no_engine). (Was contradicting its own Owns.) - react.dag Status T-4.6 -> T-4.7; coordination.dag Status T-4.7 -> T-4.8 (header/TASKS single-authority drift, same class as the formats fix). Doc zero-deferrals closures (v4-close-interrogation.md): - §13 ingestion orchestrator = 00_compile.dag (T-10) sole owner; no new 00_ingest (C5 direction-agnostic; substrate extension = STOP). - §16 coordination anchor = external (Wikipedia), PR/memory demoted to rationale (matches the coordination.dag header fix). - C6 owner = std/cardinality.dag (T-3); no new std/measure.dag. fmt clean; v2->v4 bootstrap viability OK (57 modules, 0 diagnostics). Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Summary
This PR is a structural commitment, not implementation. It establishes v4 as the synthesis of what v2 proved (1-residual self-host) and what v3 attempted (modeling depth + substrate refinement), with the structural fix to v3's hierarchy/gaming failure mode applied from day 1.
Two distinct moves, two commits:
Restore
src/v2/(commit818695a0f) for honest v2-vs-v3 comparison. v2 was deleted in commit39ba75728(R3 gate Daglang compiler scaffolding #42, PR R3 gate #42: delete src/v2/ directory (T-V2-Retirement G-2) #2693). Restoring lets the v3 retirement trajectory be evaluated against v2's proven 1-residual shape. RootCargo.tomlworkspace entries are NOT re-added — restoration is for source comparison only.src/v4/scaffold (commita0c7a7c83) — 28 .dag files with header-only content + 3 docs (STRUCTURE.md, BRIEF_TEMPLATE.md, TASKS.md) encoding the closed-system invariants.The motivating diagnosis
Live SG-0 census at HEAD: 56 NON_TEST + 134 TEST + 2 FRAGMENTS = 192 hand-authored files vs
design-pure-bootstrap-zero.md's 0-floor target. Audit during this conversation surfaced: paper-shrink V1 (template-relocation totools/*.rs.in) and V2 (module-relocation topub mod) gamed the SG-0 ratchet across cycles 4/5/6 (PRs #3046/#3048/#3056/#3057/#3058) before being caught + reverted. Root cause is doc-tier authority decorated, execution-tier framework gamed (perfeedback_doc_authority_must_propagate_to_execution_authority): SELF_HOSTING.md §2 4-step discipline never propagated into §1.8 ledger rows or Mgr-tier lanes; workers rationally optimized for the closest legible signal (ratchet count drop) which the file-relocation patterns satisfy.180 → 0 in 6 weeks with unknown gaming residue is untenable as a quality release. v4 is the honest move.
What v4 does differently (structurally)
The closed-system invariants make v3's failure modes structurally impossible at worker tier:
tools/*.rs.in) is forbidden by file-tree closure04_infer.dagis ONE file (vs v2's 12-file04_*cluster); split = substrate design escalationworkflow/*.dag(5 files) is implemented BEFORE any compiler work, so every WorkerOutput is a typed instance declaring which substrate fact dissolves which prior residual; gaming is impossible-by-construction, not impossible-by-process-disciplineworkflow/retirement.dagdefinesretired: HandResidual -> Witness<RetirementProof>; the SG-0 ratchet reads this predicate, not list lengthThis is the recursive-flex move (THESIS Self-hosting facet 4) applied to the work-direction layer itself, which v3 omitted.
File tree (closed system)
Total: 28 .dag scaffold files + 3 docs + 2 .gitkeep = 33 files at scaffold time.
15 XL task plan
See
src/v4/TASKS.mdfor the full execution graph. Highlights:Each XL task is a bounded modeling unit (3-10 days). Gaming surface is structurally bounded because adding files / splitting files / reaching outside declared substrate all require operator escalation. v4-done = T-15 completes with 0 hand-authored Rust + bit-identical self-host.
Bootstrap chain
Test plan
🤖 Generated with Claude Code