Skip to content

v4 D4 + D5 — ratify GroundingMap-home (resolver.dag) + operator-driven frozen-header reconcile - #3216

Merged
briansrls merged 3 commits into
mainfrom
merry-ibex-337/d2-d6-ratify
May 17, 2026
Merged

briansrls merged 3 commits into
mainfrom
merry-ibex-337/d2-d6-ratify

Conversation

@briansrls

@briansrls briansrls commented May 16, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Encodes two operator ratifications (2026-05-16) into the DECISIONS.md ledger.

D4 — GroundingMap-home. The D2 resolver's shared types live in one new file extdeps/languages/resolver.dag (Option 3) — not re-declared per language (parallel-declaration P2 forbids), not homed in rust.dag (would make a language file a substrate authority for the other four). GroundingMap<IRCarrier> is its first resident; strict admission rule = structurally-language-invariant resolver types only. Completes D2. Closed-tree extension: the resolver.dag file + STRUCTURE.md count land in the resolver.dag creation PR (T-4 lane); per-language files add a one-line import + grounding instances (the fan-out).

D5 — operator-driven frozen-header/contract reconcile is sanctioned in-PR. "Preserve-verbatim" forbids unsanctioned worker contract-drift, not sanctioned reconciliation. When an operator-tier action (a BLOCKING finding / ruling) moves a body past its frozen header or I/O contract, the header/contract is reconciled in the same PR, flagged HEADER RECONCILE. Already operating (integer.dag #3190; #3209 finding 2) — this names it the standing rule.

(Naming: these are the operator-decision-queue items "D-2" / "D-6"; the DECISIONS.md IDs continue the D-series — D1/D2/D3 are taken — so they encode as D4 / D5.)

Changes

  • src/v4/DECISIONS.md — two new Part 1 rows (D4, D5).

Test plan

  • Doc-only (DECISIONS.md ledger). No .dag, no code.

🤖 Generated with Claude Code

@briansrls briansrls changed the title v4 design v4 D4 + D5 — ratify GroundingMap-home (resolver.dag) + operator-driven frozen-header reconcile May 16, 2026
@briansrls
briansrls marked this pull request as ready for review May 16, 2026 23:58
briansrls added a commit that referenced this pull request May 17, 2026
…erator-tier review actions)

Per DECISIONS.md D5 / PR #3216 standing rule (merry-ibex-337 -> Lane B,
#3190 precedent): operator-tier action moving the body past the frozen
header/I/O ⇒ reconcile the header in the SAME PR + HEADER RECONCILE
block citing it; verbatim-while-divergent body = forbidden unsanctioned
drift.

Operator-tier actions = briansrls inline BLOCKING (ci.dag:198
C4-fabrication; ci.dag:120 single-authority-seam) + openai-pro. They
moved the body to: ci.yml is the ratified Workflow carrier under
WorkflowRuntime=YamlStatic via project_github_actions; C4 gated on the
missing v4 Workflow substrate (interim hand-authored bridge until then).
Reconciled the frozen Owns "emission target" + C4 lines from
emit(CiPipeline)/`.dag walks CiPipeline emits YAML` to the
single-authority Workflow-carrier projection; added HEADER RECONCILE
block. C4 operator-ratified INTENT preserved; only projection
mechanism/source corrected, no scope expansion. bootstrap.dag frozen
header preserved verbatim (its "ordered step sequence" I/O contract is
unchanged by the singleton redesign — correct D5 application).
Structural v2-compile gate GREEN (64 modules, 0 diagnostics).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: ecf7098a · Trigger: schedule
  • Thinking: 195s wall

Non-blocking — Strengths

  • src/v4/DECISIONS.md D4 and D5 preserve the single-authority shape: resolver shared carriers get one constrained home, and frozen-header reconciliation requires an operator-cited same-PR receipt.

✅ No blocking concerns.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: openai-pro / gpt-5-5-pro
  • Commit: e6934a16 · Trigger: manual
  • Comparison: main @ df121272 ... merry-ibex-337/d2-d6-ratify @ e6934a16
  • Conversation: View conversation

1. Story of the diff

This PR is a decision-ledger ratification in src/v4/DECISIONS.md, not an implementation patch. It adds D4 to settle where shared language-resolver substrate belongs: a single extdeps/languages/resolver.dag authority for structurally language-invariant resolver carriers, with per-language files only importing that shared carrier and declaring their own grounding rows (src/v4/DECISIONS.md:60). It also adds D5 to clarify frozen-header discipline: frozen scaffold headers remain binding for workers, but when an operator-tier action legitimately changes the body or I/O contract, the header/contract must be reconciled in the same PR with an explicit HEADER RECONCILE block (src/v4/DECISIONS.md:61).

2. Invariant categories

  1. LAYER MODEL (substrate vs implementation).

Compliant — this touches substrate-design authority, but only at the decision-ledger layer: D4 explicitly centralizes shared resolver substrate in extdeps/languages/resolver.dag instead of making Rust or any one language file the authority (src/v4/DECISIONS.md:60). That preserves the layer split between shared resolver carriers and per-language realization facts.

  1. INVARIANTS.md + modeling-discipline.md.

Compliant — P2 single-authority / no parallel authority is handled directly: D4 says shared resolver types live in “ONE new file” and are “NOT re-declared per language,” while spec-varying facts remain per-language (src/v4/DECISIONS.md:60). That matches the invariant that facts live in exactly one authoritative place and consumers should not choose among parallel sources. chatgpt-review-d55e19fb-dfc0-44…

D5 also preserves P5 progress discipline by allowing reconciliation only when an operator-tier action drove the change, and requiring same-PR documentation rather than silent scaffold drift (src/v4/DECISIONS.md:61).

  1. CODING.md.

N/A — the diff adds no Rust code, functions, methods, hidden state, or error/result shapes; CODING.md implementation-style checks are not exercised.

  1. TESTING.md.

N/A — the diff is a decision-ledger update only, with no runtime behavior or testable implementation surface. The next implementation PR for resolver.dag / per-language grounding rows should carry behavior or structural receipts, but this ratification itself does not need tests.

  1. LOCKED DESIGN DECISIONS.

Compliant — this PR is the explicit amendment point: both rows are marked operator-ratified and live in DECISIONS.md, so the lock is updated in the authority rather than being implied by scattered worker docs (src/v4/DECISIONS.md:60, src/v4/DECISIONS.md:61).

  1. TRACKED vs UNTRACKED DEBT.

Compliant — D4 is not an open-ended scaffold: it gives a bounded admission rule for resolver.dag (“ONLY structurally-language-INVARIANT resolver types”) and keeps spec-varying facts per-language (src/v4/DECISIONS.md:60). D5 likewise prevents untracked drift by requiring an operator action plus same-PR HEADER RECONCILE block; it does not authorize free header edits (src/v4/DECISIONS.md:61).

2.5. Top-down PM intent review

Compliant. The highest-level intent is preserved: the thesis wants target-language realization to be driven by language specs, with target facts in dsl/extdeps/languages/, not compiler-side special cases or per-target emitter drift; D4 reinforces that by making shared resolver carriers a single .dag authority and leaving language-specific grounding instances in language files (src/v4/DECISIONS.md:60). chatgpt-review-e04d4799-d541-44…

It also supports the grounding-completeness claim that target primitives are structurally grounded and fail closed when ungrounded, instead of becoming name-keyed lookup shortcuts. chatgpt-review-e04d4799-d541-44…

D5 preserves PM intent around disciplined operator control: reconciliation is allowed only when the operator has already moved the contract, so frozen scaffolds do not become a loophole for worker-level drift (src/v4/DECISIONS.md:61).

3. Verdict

APPROVE. The diff is narrow and consistent with the project’s single-authority and grounding direction. I did not find a diff-cited invariant violation; the main implementation obligations are correctly deferred to the future resolver.dag / per-language grounding PRs rather than being partially scaffolded here.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: e6934a16 · Trigger: schedule
  • Thinking: 189s wall

✅ Design/docs-only change; no blocking concerns against THESIS, INVARIANTS P2/P5, or the v4 decisions ledger.

@briansrls
briansrls merged commit ba9337f into main May 17, 2026
7 checks passed
briansrls added a commit that referenced this pull request May 17, 2026
…dit directive)

Per still-hawk-102 → Lane B directive (HOLD all PRs for operator audit;
de-prose in-PR; load-bearing files keep structured header contract).
Collapsed the review-cycle-accreted body modeling-notes essays to terse
load-bearing comments (CODING.md "default no comments; only non-obvious
WHY"): bootstrap.dag 257→173, ci.dag 508→374. Comment-only — code,
types, fns, data unchanged; structural v2-compile gate GREEN (64
modules, 0 diagnostics).

KEPT (mandated artifacts, not de-prosed): the immutable structured
headers (Scope/Anchor/Owns/A3/Discipline/Consumes/Status/Brief); the
ci.dag D5 HEADER RECONCILE block (#3216 standing rule); TRACKED SCAFFOLD
owner/trigger items; the WELL-FORMEDNESS eager-boundary doc incl. the
Map-infeasibility one-liner (Lane-B-mandated visible) + still-hawk-102
adjudication provenance; ledger-provenance + supersession one-liners;
no-fabrication/single-authority + command-non-executable facts.
REMOVED/COLLAPSED: multi-paragraph restated rationale, defensive
review-cycle elaboration. RELOCATE: n/a (no in-scope target; design
narrative already captured in PR comments + DECISIONS). No D2-alias
prose present (verified — file is not D2-affected, no D2 reconcile).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 17, 2026
…directive, interim until #3226)

Per still-hawk-102 STRICT DE-PROSE RE-DO (supersedes prior nominal
de-prose; prior attestation not accepted). A de-prosed .dag carries
ONLY: file-path line; terse Scope/Owns/Consumes/Status header; optional
per-carrier Anchor URL; optional one-line per-TYPE concept tag if
non-obvious. Everything else removed. Comment-only — all code, types,
fns, data verbatim-unchanged; structural v2-compile gate GREEN (64
modules, 0 diagnostics).

Comment-% (was → now): bootstrap.dag ~83% → 19.2% (5/26);
ci.dag ~58% → 3.2% (5/156). Both < 20% hard target.

PROCESS RECEIPT / removed-narrative provenance (kept here in the commit
message per directive, NOT in the file):
- ci.dag D5 HEADER RECONCILE (2026-05-17, #3213, D5/#3216, #3190
  precedent): operator-tier BLOCKING review actions (briansrls inline
  C4-fabrication + single-authority-seam; openai-pro confirming) moved
  the body past the frozen Owns/C4 header; it was reconciled IN-PR to
  the single-authority project_github_actions->Workflow seam with C4
  gated on the missing v4 Workflow substrate (interim hand-authored
  ci.yml bridge). C4 operator-ratified intent preserved; only mechanism
  corrected. This narrative now lives only in git history + prior PR
  comments, not the file.
- ci_pipeline_well_formed is the eager fail-closed well-formedness
  boundary (still-hawk-102 adjudication 2026-05-17): #3162 does not
  govern CiPipeline (intrinsic statically-decidable well-formedness);
  structural Map-for-ids INFEASIBLE (v4 Map<K,V> is lookup-only, no key
  enumeration) so jobs/gates stay List + eager predicate checks unique
  ids (node.dag all_names_distinct precedent) + ref-resolution +
  acyclicity (Kahn elimination bounded by count(jobs), A2-IMPLICIT,
  P4-decidable). Architectural rationale belongs in DECISIONS.md (owned
  by operator/#3226), not this file.
- No D2-alias prose present (not D2-affected, not pipeline-stage); no
  gated reconciliations. Branch 0 commits behind origin/main.

HELD for operator audit; not merging (operator squash-merge only).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 18, 2026
…apPlan data + CiPipeline C4 seam) (#3213)

* v4 T-20+T-24: model workflow/bootstrap.dag + workflow/ci.dag — BootstrapPlan data (v2-interp) + CiPipeline C4 ci.yml projection seam

T-20 workflow/bootstrap.dag: Stage / BootstrapStep / BootstrapPlan as
inert data; canonical seed→self0→self1→fixpt plan. Interpretation
(process/fs spawn) + executable BitIdentical TestClaim deferred (TRACKED
SCAFFOLD; owners T-22/T-4.5 and T-15).

T-24 workflow/ci.dag: CiJob / CiGate / CiPipeline data; Symbol-edge job
DAG; canonical structural v2-compile gate instance (the existing day-1
gate). ci.yml C4 projection, affected-set selection (IB-2), and
test/eval lane deferred (TRACKED SCAFFOLD; owners T-4.6/T-10, T-21, T-22).

Structural v2-compile gate verified: v2-compiler indexes 64 modules,
0 diagnostics. Status-line bump only; Owns/Consumes/Scope/Anchor headers
unchanged.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 T-20: add Practice-4 🟢/🟡/🔴 + five-pattern ledger to Stage + BootstrapStep coproducts

Addresses BLOCKING review (bootstrap.dag:160): every substrate coproduct
must carry the full Practice-4 classification + five-pattern dissolution
ledger under INVARIANTS P1 / modeling-discipline.md §4. Both Stage and
BootstrapStep classified 🟢 GREEN (terminal) with the five patterns
(fact-placement / variant-is-data / algebraic / dimensional /
parameterized-family) attempted inline, mirroring the witness.dag
exemplar. The inadequate one-line note replaced with a forward pointer.
Comment-only; structural v2-compile gate re-verified (64 modules, 0
diagnostics).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 T-20: make the bootstrap chain structural — fixed record replaces List<BootstrapStep>

Addresses BLOCKING review (bootstrap.dag:190): steps: List<BootstrapStep>
admitted reordered/duplicated/missing/extra chains — the
seed-once→stage0→stage1→stage2→fixed-point invariant was prose-only
(INVARIANTS P2). The chain is fixed by STRUCTURE.md (zero degrees of
freedom), so BootstrapPlan is now a FIXED RECORD with four named
positional slots whose distinct slot TYPES (CompileStep / FixedPointStep)
pin compile-vs-fixedpoint per position. Dissolves the exact node.dag
Diff #3162 list-anti-pattern. BootstrapStep coproduct removed (kind is
now the slot type, not a variant); Stage coproduct + its Practice-4
ledger retained unchanged (still consumed by the step records — no
finding-#1 churn). Within-step Stage wiring is a documented bounded
residual (yaml lexeme class; mis-wire = fail-closed interpret-time
Diagnostic, the ratified Diff stance — not a type-level illegal state).
Structural v2-compile gate re-verified (64 modules, 0 diagnostics).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 T-24: make the C4 ci.yml claim honest — no fabrication of GHA transport facts

Addresses BLOCKING review (ci.dag:146): CiPipeline {jobs,gates} cannot
faithfully back a .github/workflows/ci.yml C4 projection — a faithful
GHA workflow needs on/runs-on/steps/concurrency/permissions, which the
gunbc job/gate DAG deliberately omits, so any CiPipeline->ci.yml emit
would fabricate them (INVARIANTS P1/P2).

Fix is honesty, not fabrication and not a substrate add: project_ci_yml
re-typed to also consume a GHA workflow-schema model (gunbc data fills
the schema, never invents it); that schema is named MISSING SUBSTRATE
(no v4 counterpart to v3 extdeps/github/actions.dag — a new file =
operator-tier, surfaced not added). Committed ci.yml reframed as the
explicit interim hand-authored BRIDGE (the affected_set.dag
detect-affected-components.sh precedent); C4 checked-projection is an
explicit future state gated on the named substrate. The immutable
header's Owns/C4-over-CiPipeline over-claim is flagged on the PR for
conscious operator confirmation (frozen-header lines NOT worker-edited).
Structural v2-compile gate re-verified (64 modules, 0 diagnostics).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 T-20: comment hygiene — drop stale BootstrapStep refs from current-tense prose

Addresses cursor/composer-2 APPROVE_WITH_COMMENTS: two comments still
named BootstrapStep in the present tense after it was dissolved into
CompileStep/FixedPointStep slots. Fixed the "DATA, not a runner"
paragraph (now: fixed BootstrapPlan record of named slots) and the
Stage ledger pattern-1 (now: every chain step CompileStep/FixedPointStep).
The two remaining BootstrapStep mentions are intentional
removal-provenance, kept. Comment-only; structural v2-compile gate
re-verified (64 modules, 0 diagnostics).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 T-24: defer C4 seam to the ratified single-authority Workflow path (not a worker-minted shape)

Addresses BLOCKING (ci.dag:120): the db725fc C4 fix minted a parallel
project_ci_yml(CiPipeline, GhaWorkflowSchema) -> YamlValue seam,
diverging from the ratified locked T-Workflow-As-Data path
project_github_actions(CIWorkflowDag, WorkflowRuntime) -> Workflow
(extdeps.github.actions { Workflow } single authority pinned on
gunbc.ci CIWorkflowDag; WorkflowRuntime = YamlStatic | BinaryShim;
dsl/gunbc/ci_emission.dag) — parallel authority, INVARIANTS P2 (the
SELF_HOSTING authority-audit precedent).

Fix: the deferred seam now defers to the ratified single-authority
Workflow carrier + project_github_actions/WorkflowRuntime seam; ci.yml
is the Workflow carrier serialized under YamlStatic (YAML downstream of
Workflow), never a parallel CiPipeline -> YamlValue projection. The
invented GhaWorkflowSchema/project_ci_yml shape is retracted (kept as
provenance, not silently dropped). Missing substrate re-stated as the
v4 counterpart of the ratified extdeps.github.actions Workflow carrier
+ ci_emission.dag seam (operator-tier new file, surfaced not added, not
worker-substituted). No-fabrication / interim-bridge / header-tension-
surfaced stance preserved. Structural v2-compile gate re-verified (64
modules, 0 diagnostics).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: IB-3 T-20+T-24 workflow/bootstrap.dag + workflow/ci.dag — BootstrapPlan

* v4 T-20: make bootstrap chain edge identity structural now (singleton steps; zero inhabitants of invalid plans)

Addresses openai-pro REQUEST_CHANGES (843a37f, the binding gate) +
operator P2 finding: the free-field CompileStep/FixedPointStep records
still admitted the exact mis-wiring (seed slot typed-valid with
produces:Stage2) the comments claimed eliminated — the source/target
edge is the fixed chain's structural identity, not user config, so it
must be structural NOW, not an interpret-time check.

Each of the four positions is now its own payload-less SINGLETON
edge-identity type (SeedToStage0 / Stage0ToStage1 / Stage1ToStage2 /
FixptStage1Stage2; verified v2 parses `type X = X`). BootstrapPlan is
the fixed record of those slots → exactly ONE inhabitant; reorder /
duplicate / missing / extra / mis-wire all unconstructible. The Stage
coproduct (+ its five-pattern ledger) and BootstrapStep are both
removed (stage/edge identity now in the singleton names); no coproduct
remains so no Practice-4 ledger applies — this moots the earlier
"Stage/BootstrapStep need ledgers" finding by dissolution. The earlier
"bounded residual / future-grammar" deferral is retracted as
unnecessary (provenance kept, not silently dropped). Structural
v2-compile gate re-verified (64 modules, 0 diagnostics).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 T-20: fix singleton step types — empty-record form (constructible); restores green gate

bfc8886 used `type X = X` which v2 parses as a type but provides NO
usable value constructor (`undefined variable` at the data
construction) — that commit broke the structural v2-compile gate (4
errors). Root cause: the earlier probe only DECLARED the singleton,
never CONSTRUCTED it. Fixed: the four chain-position singletons are
empty records `type X {}` constructed as `X {}` (verified: v2 parses
AND constructs this form, 0 diagnostics). Design intent unchanged —
BootstrapPlan still has exactly one inhabitant; mis-wiring
unconstructible (openai-pro REQUEST_CHANGES + operator P2 resolved
structurally). Prose updated (empty-record singleton, not `type X = X`).
Structural v2-compile gate re-verified GREEN (64 modules, 1 file
emitted, 0 diagnostics, no errors).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 T-24: D5 in-PR frozen-header reconcile for ci.dag Owns/C4 (cite operator-tier review actions)

Per DECISIONS.md D5 / PR #3216 standing rule (merry-ibex-337 -> Lane B,
#3190 precedent): operator-tier action moving the body past the frozen
header/I/O ⇒ reconcile the header in the SAME PR + HEADER RECONCILE
block citing it; verbatim-while-divergent body = forbidden unsanctioned
drift.

Operator-tier actions = briansrls inline BLOCKING (ci.dag:198
C4-fabrication; ci.dag:120 single-authority-seam) + openai-pro. They
moved the body to: ci.yml is the ratified Workflow carrier under
WorkflowRuntime=YamlStatic via project_github_actions; C4 gated on the
missing v4 Workflow substrate (interim hand-authored bridge until then).
Reconciled the frozen Owns "emission target" + C4 lines from
emit(CiPipeline)/`.dag walks CiPipeline emits YAML` to the
single-authority Workflow-carrier projection; added HEADER RECONCILE
block. C4 operator-ratified INTENT preserved; only projection
mechanism/source corrected, no scope expansion. bootstrap.dag frozen
header preserved verbatim (its "ordered step sequence" I/O contract is
unchanged by the singleton redesign — correct D5 application).
Structural v2-compile gate GREEN (64 modules, 0 diagnostics).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 T-24: update HEADER TENSION para to reflect completed D5 reconcile (codex non-blocking nit)

codex (e86a8c4, "no blocking concerns remain") flagged that the
HEADER TENSION paragraph still described the frozen header as unedited
— stale/contradictory after the D5 in-PR reconcile (5f306e2). Updated
the para from "SURFACED, worker does NOT edit frozen lines" to
"RECONCILED in-PR (D5)" pointing at the HEADER RECONCILE block. Comment
hygiene only; no model change. Structural v2-compile gate GREEN (64
modules, 0 diagnostics).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 T-24: make CiJob.command faithful + explicitly non-executable (codex BLOCKING)

codex BLOCKING (sha 99753a3): CiJob.command was a lossy paraphrase
("v2-compiler compile --source-root src/v4") while documented as the
command line the deferred interpreter executes — fabricating process
facts (INVARIANTS P1) and not faithfully reproducing the live v4 CI
gate command.

Fix (both options the finding allowed): (a) store the EXACT primary
gate invocation verbatim from .github/workflows/ci.yml
("target/release/v2-compiler compile --source-root src/v4 --output-dir
/tmp/v4-stage1 --target dag"); (b) reframe the field as NON-EXECUTABLE
documentation data — there is no interpreter (process carrier
extdeps/process.dag is T-4.5 scaffold) and a single String cannot carry
a GHA job (the live step is a multi-line shell wrapper + a `cargo build`
prerequisite). The full faithful step + process spawn stay deferred to
extdeps/process.dag (T-4.5) + T-22 (TRACKED SCAFFOLD (3)), explicitly
NOT fabricated into the String. Field doc + CiJob doc + gate-instance
comment updated. Structural v2-compile gate GREEN (64 modules, 0
diagnostics).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 T-20: unify fixed-point vocab in body — bit-identical (property) + RoundTrips (AssertKind)

cursor APPROVE_WITH_COMMENTS (non-blocking): body prose said
"`BitIdentical` TestClaim" (implying a kind) in places while the TRACKED
SCAFFOLD correctly ties the deferred check to std/verification.dag
`kind: RoundTrips` (no `BitIdentical` AssertKind exists). One editorial
pass: all BODY occurrences now use "bit-identical" for the
stage1==stage2 PROPERTY and `RoundTrips` for the substrate AssertKind
(Status note, WHY-PINNED-HASH note, FixptStage1Stage2 type comment;
TRACKED SCAFFOLD (2) was already correct). Frozen Owns/Consumes header
lines (22/26/76) preserved VERBATIM — a non-blocking hygiene nit is not
the operator-tier D5 sanction required to edit frozen header lines;
"BitIdentical" there is the property/anchor name, reconcilable with
verification.dag's RoundTrips ("self-host bit-identity") once the body
is consistent. Comment-only; structural v2-compile gate GREEN (64
modules, 0 diagnostics).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 T-24: name the fail-closed CiPipeline well-formedness boundary (node.dag Diff #3162 stance)

Addresses briansrls BLOCKING (ci.dag:275): jobs/gates lists + raw
Symbol edges leave missing targets / duplicate ids / needs-cycles
constructible; P2/P4 need a structural OR fail-closed boundary before
consumers land.

Resolved by applying the canonical node.dag Diff #3162 ratification
(not a coin-flip — that precedent settles the shape): ANY jobs/gates
lists are valid CiPipeline DATA; missing-target/dup-id/cycle are NOT
type-level illegal states and there is deliberately NO
ci_pipeline_well_formed eager predicate (exactly the #3162
diff_well_formed anti-pattern). The fail-closed WELL-FORMEDNESS
boundary is the deferred select_jobs consume fold (apply_diff-analogous
all-or-nothing): unresolved/duplicate/cyclic => one fail-closed
Diagnostic (Outcome<T>), decidable via visited-set traversal (P4).
NAMED + OWNED now (select_jobs / lens/affected_set.dag T-21, TRACKED
SCAFFOLD (2)); only its body deferred per scaffold discipline. Doc
tightened in CiPipeline + TS(2). Comment-only; structural v2-compile
gate GREEN (64 modules, 0 diagnostics).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: IB-3 T-20+T-24 workflow/bootstrap.dag + workflow/ci.dag — BootstrapPlan

* v4 T-24: implement eager fail-closed ci_pipeline_well_formed boundary (still-hawk-102 adjudication)

still-hawk-102 (relayed via Lane B) rejected reaffirming #3162 for
CiPipeline: #3162's precondition (no intrinsic well-formedness) is FALSE
here — a job/gate DAG has intrinsic, statically-decidable
well-formedness (unique ids / acyclic / resolving refs), malformed
independent of any consumer; deferring to select_jobs (a consumer) is
ruled out by the operator's "before consumers land". Patterns don't
auto-extend without the per-instance precondition.

Implemented the eager boundary NOW: ci_pipeline_well_formed :
CiPipeline -> Outcome<CiPipeline>, covering (1) unique job ids
(node.dag all_names_distinct CHECK-enforced precedent), (2) reference
resolution (every needs/gate.job resolves to a declared id), (3)
acyclicity via Kahn sink-elimination bounded by count(jobs) passes
expressed as a fold over the finite jobs list (A2 IMPLICIT termination,
INVARIANTS P4) — never an unbounded walk. Any violation = one
fail-closed Diagnostic (AmbiguousIntent, no repair-guess). Structural
Map-for-ids was INFEASIBLE: v4 Map<K,V> is lookup-only (no key
enumeration) so a Map jobs field can't be traversed for the required
acyclicity/ref checks; jobs/gates stay List (fold-traversable) per the
adjudication's "pick by feasibility" + ACCEPTABLE eager option. NOT a
#3162 exception (#3162 never governed this carrier). WELL-FORMEDNESS
header + TRACKED SCAFFOLD (2) rewritten (drop #3162-stance + the
deferral). Structural v2-compile gate GREEN (64 modules, 0 diagnostics).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: IB-3 T-20+T-24 workflow/bootstrap.dag + workflow/ci.dag — BootstrapPlan

* v4 T-20+T-24: de-prose bootstrap.dag + ci.dag in-PR (operator HOLD/audit directive)

Per still-hawk-102 → Lane B directive (HOLD all PRs for operator audit;
de-prose in-PR; load-bearing files keep structured header contract).
Collapsed the review-cycle-accreted body modeling-notes essays to terse
load-bearing comments (CODING.md "default no comments; only non-obvious
WHY"): bootstrap.dag 257→173, ci.dag 508→374. Comment-only — code,
types, fns, data unchanged; structural v2-compile gate GREEN (64
modules, 0 diagnostics).

KEPT (mandated artifacts, not de-prosed): the immutable structured
headers (Scope/Anchor/Owns/A3/Discipline/Consumes/Status/Brief); the
ci.dag D5 HEADER RECONCILE block (#3216 standing rule); TRACKED SCAFFOLD
owner/trigger items; the WELL-FORMEDNESS eager-boundary doc incl. the
Map-infeasibility one-liner (Lane-B-mandated visible) + still-hawk-102
adjudication provenance; ledger-provenance + supersession one-liners;
no-fabrication/single-authority + command-non-executable facts.
REMOVED/COLLAPSED: multi-paragraph restated rationale, defensive
review-cycle elaboration. RELOCATE: n/a (no in-scope target; design
narrative already captured in PR comments + DECISIONS). No D2-alias
prose present (verified — file is not D2-affected, no D2 reconcile).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 T-20+T-24: STRICT de-prose bootstrap.dag + ci.dag (still-hawk-102 directive, interim until #3226)

Per still-hawk-102 STRICT DE-PROSE RE-DO (supersedes prior nominal
de-prose; prior attestation not accepted). A de-prosed .dag carries
ONLY: file-path line; terse Scope/Owns/Consumes/Status header; optional
per-carrier Anchor URL; optional one-line per-TYPE concept tag if
non-obvious. Everything else removed. Comment-only — all code, types,
fns, data verbatim-unchanged; structural v2-compile gate GREEN (64
modules, 0 diagnostics).

Comment-% (was → now): bootstrap.dag ~83% → 19.2% (5/26);
ci.dag ~58% → 3.2% (5/156). Both < 20% hard target.

PROCESS RECEIPT / removed-narrative provenance (kept here in the commit
message per directive, NOT in the file):
- ci.dag D5 HEADER RECONCILE (2026-05-17, #3213, D5/#3216, #3190
  precedent): operator-tier BLOCKING review actions (briansrls inline
  C4-fabrication + single-authority-seam; openai-pro confirming) moved
  the body past the frozen Owns/C4 header; it was reconciled IN-PR to
  the single-authority project_github_actions->Workflow seam with C4
  gated on the missing v4 Workflow substrate (interim hand-authored
  ci.yml bridge). C4 operator-ratified intent preserved; only mechanism
  corrected. This narrative now lives only in git history + prior PR
  comments, not the file.
- ci_pipeline_well_formed is the eager fail-closed well-formedness
  boundary (still-hawk-102 adjudication 2026-05-17): #3162 does not
  govern CiPipeline (intrinsic statically-decidable well-formedness);
  structural Map-for-ids INFEASIBLE (v4 Map<K,V> is lookup-only, no key
  enumeration) so jobs/gates stay List + eager predicate checks unique
  ids (node.dag all_names_distinct precedent) + ref-resolution +
  acyclicity (Kahn elimination bounded by count(jobs), A2-IMPLICIT,
  P4-decidable). Architectural rationale belongs in DECISIONS.md (owned
  by operator/#3226), not this file.
- No D2-alias prose present (not D2-affected, not pipeline-stage); no
  gated reconciliations. Branch 0 commits behind origin/main.

HELD for operator audit; not merging (operator squash-merge only).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 T-24: ci_pipeline_well_formed also proves gate-id uniqueness (briansrls BLOCKING)

Valid finding (ci.dag:27): CiGate.id is an addressable identity but the
eager well-formedness predicate checked job-id uniqueness only, so
duplicate gate ids were accepted → ambiguous downstream selection
authority (INVARIANTS P2). Same intrinsic, statically-decidable,
consumer-independent well-formedness class the still-hawk-102
adjudication required for jobs.

Fix (code-only; strict-de-prose preserved, ci.dag 2.9% comment):
added ci_gate_id_occurrences + ci_all_gate_ids_unique (mirroring the
job-id check / node.dag all_names_distinct CHECK-enforced precedent) +
a ci_duplicate_gate_id reason symbol, and a gate-id-uniqueness branch
in ci_pipeline_well_formed (duplicate gate id ⇒ fail-closed Rejected).
Structural v2-compile gate GREEN (64 modules, 0 diagnostics).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 T-24: fix ci.dag Consumes header drift (std/* → v4.std.*)

cursor APPROVE exploratory nit: terse Consumes header said `std/node,
std/diagnostic` but the actual imports are `v4.std.node` /
`v4.std.diagnostic`. The terse header is now the sole in-file contract
under operator audit, so header precision matters. One-line accuracy
fix; strict de-prose preserved; structural v2-compile gate GREEN (64
modules, 0 diagnostics).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 T-20: expand bootstrap.dag four stages as v4 orchestration DATA (operator directive; resolves codex finding-1)

Operator (still-hawk-102 via loyal-wren-802) adjudicated codex #3213
finding-1: bootstrap.dag DOES own/define/source/orchestrate the four
stages now (supersedes the prior minimal-singleton/deferred-interpret
framing). Expanded per directive:

- DEFINE: each stage is a distinct record with real fields (no more
  empty `{}` markers). SeedToStage0/Stage0ToStage1/Stage1ToStage2 carry
  consumes/produces/via; FixptStage1Stage2 carries left/right/via.
- SOURCE: inputs are real Symbol identities — v4_dag_source (the src/v4
  .dag compiler corpus), v4_stage0/1/2_binary, v2_pipeline (the frozen
  seed executor), bit_identical_check. `Consumes: none` → v4.std.node.
- ORCHESTRATE: BootstrapPlan record + canonical bootstrap_plan wiring
  the four stages with concrete consumes/produces in order, as v4 DATA.
- TRIVIAL v2-DELEGATING BODIES (sanctioned): all compile stages'
  executor `via = v2_pipeline` initially; per-stage shift
  delegate-to-v2 → use-v4's-own as v4's pipeline is built (file FILLED
  IN, never replaced). Orchestration is v4 data from day one.

Per-position type distinctness retained (seed slot must be
SeedToStage0, etc.) so cross-position mis-wiring stays type-prevented.
No coproducts introduced (all records) — emoji-tag directive N/A.
Strict de-prose preserved: bootstrap.dag 7.1% comment (5/70), terse
4-line header only. Structural v2-compile gate GREEN (64 modules, 0
diagnostics). HELD for operator audit; in-PR expansion.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: IB-3 T-20+T-24 workflow/bootstrap.dag + workflow/ci.dag — BootstrapPlan

* WIP: IB-3 T-20+T-24 workflow/bootstrap.dag + workflow/ci.dag — BootstrapPlan

* v4 T-24: port v3 CICommand → typed v4 CiCommand carrier (still-hawk-102 fork-2; Option-1 DECISIONS row)

still-hawk-102 fork-2 directive: replace ci.dag CiJob.command:String with
a proper v4 typed command carrier, PORT (not import) of v3
dsl/gunbc/ci.dag CICommand. Faithful re-express (no shape fork):
  type CiCommand = LintCommand | TestCommand
                 | IgnoredTestCommand { test_name: String }
                 | ShellCommand { command: String }
  CiJob.command: CiCommand (was String); v2_compile_gate_job →
  ShellCommand { command: "<verbatim v2-compile invocation>" }.

Coproduct ⇒ per modeling-discipline.md Practice 4/9 + the coproduct-emoji
directive: in-file one-line tag `// 🟡 coproduct dissolution —
DECISIONS.md LB-P4-3213` on `type CiCommand`; full classification ledger
authored as DECISIONS.md Part-6 row LB-P4-3213 (id assigned by
still-hawk-102 Option-1: worker authors provisional, operator ratifies on
audit). Classification 🟡 YELLOW (scaffold): richer source nameable (the
T-4.5 extdeps/process.dag typed Command{program,args,env} carrier + v3
ROADMAP-F12); ShellCommand{command:String} is the bounded interim;
named trigger = T-4.5 typed Command carrier lands. 5 dissolution
patterns tried, recorded in the ledger row.

ci.dag strict de-prose preserved (3.3% comment, <20%). Structural
v2-compile gate GREEN (64 modules, 0 diagnostics). bootstrap.dag NOT
touched — codex F1/F2 reconciliation pending still-hawk-102 (orthogonal).
#3213 HELD for operator audit.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 T-20: bootstrap.dag F1/F2 fixes (still-hawk-102 reconciliation; implement, not rebut)

still-hawk-102 reconciled the codex CR — implement (not rebut):

F1 (Practice-3 forward chain): `via: v2_pipeline` kept (sanctioned
executor-is-v2-initially). `consumes` is now List<Symbol> carrying the
prior stage's produced artifact so the orchestration DATA is a chain,
not three independent compiles:
  seed  consumes [v4_dag_source]                       produces stage0
  self0 consumes [v4_dag_source, v4_stage0_binary]      produces stage1
  self1 consumes [v4_dag_source, v4_stage1_binary]      produces stage2
  fixpt left=stage1 right=stage2 via=bit_identical_check

F2 (Practice-7 enumerated-copy): the three identical
{consumes,produces,via} stage types (SeedToStage0/Stage0ToStage1/
Stage1ToStage2) collapsed into ONE `CompileStage { consumes, produces,
via }`. FixptStage1Stage2 { left, right, via } stays its own type (not
collapsed, per directive). Order/multiplicity expressed as fixed named
BootstrapPlan slots (seed/self0/self1: CompileStage; fixpt:
FixptStage1Stage2) — keeps the exactly-3-compiles+1-fixpt fixed shape
(no over-general List reintroduced) while removing the enumerated copy.

No coproducts (records only) — emoji directive vacuous. Strict de-prose
preserved: bootstrap.dag 8.6% (5/58), <20%. Structural v2-compile gate
GREEN (64 modules, 0 diagnostics). #3213 HELD for operator audit.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 T-24: export ci_pipeline as fail-closed Outcome (briansrls BLOCKING — non-bypassable boundary)

Valid finding (ci.dag:54): canonical `ci_pipeline` was exported as raw
CiPipeline, so consumers could read it without passing through the
operator-adjudicated eager `ci_pipeline_well_formed` boundary —
bypassing the P2/P3 fail-closed check. Faithful completion of the
still-hawk-102-directed eager-well-formedness boundary (no shape fork,
no directive conflict): the boundary now cannot be bypassed.

Fix: raw construction is internal `ci_pipeline_unchecked: CiPipeline`;
the exported canonical `ci_pipeline: Outcome<CiPipeline> =
ci_pipeline_well_formed(p: ci_pipeline_unchecked)`. Downstream consumers
must handle Produced/Rejected — the eager fail-closed boundary is now
the only way to obtain the pipeline. v2 supports the fn-application
data initializer (verified). Strict de-prose preserved (ci.dag still
<20%); structural v2-compile gate GREEN (64 modules, 0 diagnostics).
Orthogonal to the bootstrap P2/F1/F2 trilemma (routed, pending
still-hawk-102; bootstrap.dag NOT touched). #3213 HELD for audit.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: IB-3 T-20+T-24 workflow/bootstrap.dag + workflow/ci.dag — BootstrapPlan

* WIP: IB-3 T-20+T-24 workflow/bootstrap.dag + workflow/ci.dag — BootstrapPlan

* v4 T-20: bootstrap (b) expose-only-checked — drop consumable bootstrap_plan_unchecked (still-hawk-102 GO)

still-hawk-102 RULING on the openai-pro (heaviest-weight) REQUEST_CHANGES
re-litigating the adjudicated bootstrap-P2: implement (b). (a)
structural per-stage nominal identities FORBIDDEN — do not revert F2
(codex-F2 / Practice-7 stays closed).

(b): removed the named consumable `data bootstrap_plan_unchecked:
BootstrapPlan`; the BootstrapPlan{...} literal is now inlined as the
sole argument to bootstrap_plan_well_formed(p: BootstrapPlan {...}).
The ONLY named export consumers can bind is now `bootstrap_plan:
Outcome<BootstrapPlan>` (the checked carrier) — the consumable-boundary
leak (unchecked raw record had a name to grab) is closed. Mirrors the
ci_pipeline expose-only-checked precedent (Lane-B-PASSED). F1 (forward
consumes chain) + F2 (single CompileStage) intact; no codex-F2
re-trigger; no shape fork.

v2-compiler parses the inlined nested record literal (verified, not
shipped blind); structural v2-compile gate GREEN (64 modules, 0
diagnostics). Strict de-prose intact (bootstrap.dag 4.5%, <20%).
#3213 HELD for operator re-audit.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: IB-3 T-20+T-24 workflow/bootstrap.dag + workflow/ci.dag — BootstrapPlan

* v4 #3213 IB-3: Practice-10 List-op dissolution pass (operator merge gate)

std/collection.dag (T-3) declares zero derived List ops -> zero RED
(nothing to dissolve into in-PR); every hand-rolled generic List
primitive marked YELLOW gated feature: (owner T-3 std/collection.dag,
named missing op + dissolve-on-arrival obligation). Kahn composition
classified GREEN terminal domain-logic (peer of the well-formed
predicates). One terse in-file tag per file (LB-P4-3213 precedent);
full LB-P10-3213 ledger in DECISIONS.md Part 7. #3244 disposition
vocabulary. Structural v2-compile gate: indexed 67 modules, 0 diagnostics.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 #3213: ci.dag expose-only-checked — drop consumable ci_pipeline_unchecked/v2_compile_gate_job (operator REQUEST_CHANGES)

Operator (briansrls) BLOCKING: top-level raw ci_pipeline_unchecked:
CiPipeline was a second authority beside checked ci_pipeline,
bypassable by downstream consumers (P2 single-authority / P3
fail-closed). Fix mirrors the operator-accepted bootstrap (b)
expose-only-checked shape: inline the CiPipeline literal (CiJob/CiGate
inlined) as the sole arg to ci_pipeline_well_formed; remove the named
ci_pipeline_unchecked and v2_compile_gate_job composites so the only
consumable pipeline authority is data ci_pipeline: Outcome<CiPipeline>.
Header Owns updated. Structural v2-compile gate: indexed 68 modules,
0 diagnostics.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 #3213: ci.dag rename ci_kahn_fixpoint fold param counter->job (CODING.md names-describe-the-mapping)

Recurring multi-reviewer readability observation (cursor 13938
exploratory): the fold's 2nd callback parameter is the folded `jobs`
element, not a counter; `counter` misdescribed the mapping. Renamed to
`job` per CODING.md "names describe the mapping". Semantically inert
(param remains deliberately unused — the fold is the bounded-iteration
driver per LB-P10-3213-KAHN); structural v2-compile gate: indexed 68
modules, 0 diagnostics. Resolves the observation permanently rather
than restating "intentional".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 #3213: rewrite LB-P4-3213 ledger to #3244 precision (consumer-gate, landed target)

CORE ruling (still-hawk-102, Option-1 + #3244): reframe LB-P4-3213 as a
valid plan-bound 🟡 with gate kind = consumer: (first meaning-consumer of
typed-command shape, deferred-by-brief, gate CLOSED). process.dag::Command
is the LANDED migration target (#3209), not the meaning-consumer — future
consumer consumes typed Command directly; #3213 does NO migration / NO
local CiCommand parse. Anti-#3250: NOT "no change needed".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 #3213: bootstrap.dag — split stage compiler-of-record from executor (self-hosting identity)

codex BLOCKING + 2 BLOCKING-inline (P1/P2): every CompileStage.via was
v2_pipeline, conflating the orchestration executor with the stage
compiler-of-record and making the fixpt (stage1==stage2) check vacuous.

Fix grounded in load-bearing docs:
- STRUCTURE.md:404-405 "Seed used once": v2 produces v4-stage0, then v4
  compiles itself; v2 is never in the loop again.
- SELF_HOSTING.md §meta-circular: stage0 compiles source->stage1,
  stage1 compiles source->stage2, assert byte-identical.

via -> compiled_by (CODING.md names-describe-the-mapping): seed
compiled_by v2_pipeline, self0 by v4_stage0_binary, self1 by
v4_stage1_binary. No executor bridge field — STRUCTURE.md is explicit
that v2 is seed-once, so no "v2 executes every stage" fact exists; the
brief's "v2 is the initial executor" framing contradicted the doc and
the doc wins.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 #3213: ci.dag consumes bootstrap seed authority — single-authority fix (P2/Practice 5)

openai-pro 13971 (BLOCKING, at HEAD 52c207b): ci.dag:52 restated the
bootstrap seed action as a raw ShellCommand argv string, a parallel
authority for the seed→stage chain that bootstrap.dag BootstrapPlan.seed
now canonically owns — drift-prone, violates INVARIANTS P2 single-
authority / modeling-discipline Practice 5; the duplication was also
untracked debt (review §6).

Fix (in-PR, structural model only — not the brief-deferred ci.yml
projection / T-22 lane): add typed CiCommand variant
BootstrapStageCompile{produces: Symbol}; the v2_compile_src_v4 job now
references v4_stage0_binary imported from v4.workflow.bootstrap. A real
machine-readable cross-module edge to the bootstrap authority — the raw
argv is removed entirely; BootstrapPlan.seed is the sole source of
truth. No import cycle (bootstrap does not import ci).

Distinct from / orthogonal to CORE-adjudicated LB-P4-3213: that 🟡 is
the ShellCommand{String} raw-argv command-SHAPE decomposition, deferred
to the consumer lane. This is single-AUTHORITY wiring (an invariant),
resolved now. LB-P4-3213 ledger updated to record the resolution.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: IB-3 T-20+T-24 workflow/bootstrap.dag + workflow/ci.dag — BootstrapPlan

* v4 #3213: Practice-9 de-prose — in-file rationale → ≤1-line ledger pointers

cursor 13986 (NON-BLOCKING, APPROVE_WITH_COMMENTS): ci.dag mid-carrier
comment recorded single-authority/P2 rationale as in-file prose
(Practice 9 — rationale belongs in DECISIONS.md, already covered by
LB-P4-3213). Replace with a one-line `// 🟢 single-authority —
DECISIONS.md LB-P4-3213` pointer; strip the same-shape parenthetical
from ci.dag Consumes line and tighten bootstrap.dag compiled_by tag for
consistency. No semantic change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 #3213: Practice-9 — drop bootstrap.dag compiled_by field-prose

cursor 13998 (APPROVE_WITH_COMMENTS): the `// stage compiler-of-record`
field comment is rationale-on-carrier, not an allowed comment class.
The field name + header Scope line already convey the self-hosting
identity; structure speaks for itself. No DECISIONS pointer needed (no
dedicated ledger entry; header already documents seed-once semantics).
No semantic change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 #3213: structurally enforce BootstrapStageCompile single-authority at the CI boundary

openai-pro 14006 (BLOCKING, manual re-review @ 5d4468d): BootstrapStageCompile{produces:Symbol}
took an unconstrained Symbol and ci_pipeline_well_formed never validated it against the
canonical BootstrapPlan outputs — the single-authority seam the ledger claims as resolved
was prose/convention, not structural enforcement (INVARIANTS P2 / modeling-discipline
Practice 5/6).

Fix (structural model, in-scope — not the brief-deferred T-22 executable lane):
- bootstrap.dag owns bootstrap_stage_output(s: Symbol) -> Bool — the single authority on
  the canonical stage-output set {v4_stage0_binary, v4_stage1_binary, v4_stage2_binary}.
- ci.dag imports it; ci_pipeline_well_formed now consumes the bootstrap authority via
  ci_all_commands_authority_ok and fail-closed rejects any BootstrapStageCompile.produces
  outside that set (ci_bootstrap_authority_violation). A dangling payload cannot reach
  Produced — the invariant is enforced at the substrate boundary, not asserted in prose.
- LB-P4-3213 ledger updated: single-authority is now boundary-ENFORCED, not prose.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 #3213: ADDRESSED-BY-CONSTRUCTION + plan-bound 🟡 to T-22 (CORE horn (i))

still-hawk-102 ruling (2026-05-18): the BootstrapStageCompile single-
authority seam is addressed-by-construction (pure structural predicate;
out-of-set produces cannot satisfy the gate — modeled Rejected Outcome,
no imperative side-channel; verified in code @6353d695e). Horn (ii)
in-PR executable harness REJECTED (T-22-in-#3213 = brief violation).

Records the deferred executable demonstration as an explicit plan-bound
🟡 with bilateral binding:
- DECISIONS.md LB-T22-3213: arrival (T-22 TestClaim runner) + follow-up
  (negative TestClaims for the bootstrap-stage rejection family) that
  dissolves the 🟡.
- TASKS.md T-22 scope: same obligation, cross-referencing LB-T22-3213
  (neither side vague).
- ci.dag in-file one-line tag → LB-T22-3213.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 #3213: Practice-9 — single coproduct tag on CiCommand (drop variant-level 🟢)

cursor 14020 (APPROVE_WITH_COMMENTS): CiCommand carried two emoji
dissolution lines (coproduct-level 🟡 + variant-level 🟢), reading as
conflicting dispositions on one type. Rubric wants one required
🟢/🟡/🔴 tag per coproduct; the LB-P4-3213 ledger already carries the
single-authority/command-shape nuance. Drop the redundant variant-level
🟢 line; the coproduct-level 🟡 tag + DECISIONS.md ledger stand. No
semantic change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 #3213: CI bootstrap-authority consumes bootstrap_plan Outcome, fail-closed (P2/P3)

Operator BLOCKING inline (#3213 ci.dag:168): bootstrap_stage_output
checked static stage-symbol membership {v4_stage0_binary,1,2} instead of
consuming bootstrap_plan: Outcome<BootstrapPlan> — so CiPipeline could be
Produced even when the canonical bootstrap plan is Rejected, bypassing
the fail-closed bootstrap authority (INVARIANTS P2 single-authority /
P3 fail-closed).

Fix: bootstrap_stage_output now takes Outcome<BootstrapPlan>, matches it
— Rejected ⇒ false (fail-closed: CI cannot pass while bootstrap is
Rejected), Produced{value: bp} ⇒ produces ∈ {bp.seed/self0/self1
.produces} (validated-plan actual outputs, not a static set). ci.dag
imports bootstrap_plan and threads it through ci_command_authority_ok →
ci_pipeline_well_formed. The validated bootstrap_plan is now the sole
authority. LB-P4-3213 ledger updated (P2/P3, plan-Outcome consumed).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 #3213: add mandatory // Ledger: pointer line to load-bearing workflow headers

CORE ruling (still-hawk-102 via Lane B): the de-prose-vs-rail fork was
FALSE — strict de-prose stands AND one mandatory `// Ledger:` pointer
line per load-bearing file (pointer class, not prose). Adds the
CORE-specified line after Status: in bootstrap.dag + ci.dag. No body
churn; consistent with strict-de-prose (concrete ref pointer, ≤1 line).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 #3213: CORE Option B — rescind // Ledger: line, keystone wins (registry doc→files)

CORE ruling (still-hawk-102) on the openai-pro 14070 RC vs the
modeling-discipline.md:503-531 keystone contradiction: the // Ledger:
mandate is RESCINDED — strict de-prose keystone wins (header stays
exactly four lines; no see-docs/X pointer in .dag).

- bootstrap.dag / ci.dag: remove the // Ledger: line (-1 each).
- Registry moves doc→files (Practice 5, top-down): design-pure-bootstrap-zero.md
  names the two load-bearing workflow files + A3/PROOF-1/STOP-rail + C4;
  INVARIANTS.md + src/v3/SELF_HOSTING.md add short Practice-5 registry
  cross-refs. Authority flows doc→files, not per-file upward pointers.

Replays swift-ram-178 a94a312 verbatim onto the #3213 branch.
Clears openai-pro 14070; consistent with the keystone.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* v4 #3213: reconcile to authoritative trimmed spec — drop INVARIANTS.md registry para

still-hawk TRIM relay (post-a94a3123f) set the authoritative one-commit
spec = NO INVARIANTS.md edit: registry lives only in
docs/design-pure-bootstrap-zero.md + src/v3/SELF_HOSTING.md + the .dag
// Ledger: strips. 9fda2f0 over-included the INVARIANTS.md para
(replayed from the pre-trim a94a312). Drop it to conform; the two
authoritative registry homes + .dag strips stand unchanged.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls
briansrls deleted the merry-ibex-337/d2-d6-ratify branch June 1, 2026 18:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant