Repository navigation
Introduce unified resource model with manifest-based freshness tracking - #34
Merged
Merged
Conversation
This commit creates a unified resource model design that consolidates: - URGENT_codegen_upsert.md (codegen staleness detection) - design-build-resource-chain.md (build artifact dependencies) - Related TODO_hacks items (PrepLevel, extra_deps, fix_deps) Key insight: Tool acquisition (EnvOp → ToolHandle) and build artifact management follow the SAME upsert pattern (Check → Create → Resolve). The only difference is how "freshness" is determined: - Tools: binary exists on PATH - Build artifacts: content hash of inputs matches manifest The new design extends the existing Resource trait with ManagedResource for freshness checking, and replaces manual dependency wiring with declarative ResourceContract (provides/needs). Changes: - New: TODO/design-unified-resource-model.md (comprehensive design) - Moved: URGENT_codegen_upsert.md → TODONE (consolidated) - Moved: design-build-resource-chain.md → TODONE (consolidated) - Updated: design-resource-acquisition.md (cross-references) - Updated: TODO_hacks (tracking references) https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
Key design decisions clarified: - Hash scope derived from declared inputs (like Bazel), not configured - Staleness propagation falls out of DAG edges via InputPattern::Resource - Flexible ResourceScope (file, pattern, named) for granularity - Bootstrap remains special-cased for now - Unified ResourceHandle<R> for both tools and build artifacts - ExecMode (Verify/Ensure) is executor context, like DryRun - DAG is pure; manifest updates are outputs, not side effects Added detailed 8-phase implementation plan with: - Estimated scope per phase - Specific files to create/modify - Tests required - Clear before/after examples https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
This implements the core abstractions for the unified resource model that consolidates tool acquisition and build resources under a single pattern: Check → Create → Resolve. New modules in core/ir/src/resource/: - hash.rs: ContentHash type for SHA-256 freshness keys, plus HashBuilder for computing hashes from multiple inputs (files, globs, strings) - state.rs: ResourceState enum (Fresh/Stale/Missing/Error) and ExecMode (Verify/Ensure) for execution context - def.rs: ResourceDef and InputPattern for declaring resource inputs/outputs. Hash scope is derived from declared inputs (like Bazel) - manifest.rs: ResourceManifest for on-disk storage of freshness keys at target/.resource-manifest.json with atomic save/load - handle.rs: ResourceHandle<R> - unified proof of acquisition that flows through DAG edges (unifies ToolHandle and BuildResourceHandle) - managed.rs: ManagedResource trait with default implementations for check_state() and acquire() Key design decisions: - Hash scope derived from InputPattern declarations, not configured - Staleness propagation via InputPattern::Resource dependencies - Single ResourceHandle<R> type for tools and build resources - ExecMode as executor context (like DryRun), not DAG structure https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
New: core/ir/src/resource/registry.rs - ResourceRegistry for holding resource definitions - Topological sort via resolve() and resolve_all() - Cycle detection with helpful error messages - Direct dependency lookup via direct_deps() - Graph acyclicity check via check_acyclic() Also added: TODO/design-resource-performance.md - Documents known performance considerations - Hash computation on every check (future: mtime caching) - Glob expansion cost (future: cache results) - Manifest entry enhancement plan (store file list) - Optimized freshness check design (fast path/slow path) Tests include linear chains, diamond dependencies, cycles, missing resources, and multi-target resolution. https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
After successful codegen, write a manifest entry for `build:generated_cli` recording the content hash of codegen inputs. This enables CI to check freshness using the manifest instead of file existence hacks. Changes to core/codegen/src/main.rs: - Import resource manifest types from gunbc_ir::resource - compute_codegen_input_hash(): Hash codegen and IR source files - write_codegen_manifest(): Write manifest entry with outputs - update_manifest_after_codegen(): Called after successful codegen - cmd_codegen and cmd_commit now update manifest on success The manifest is written to target/.resource-manifest.json with: - Resource ID: build:generated_cli - Key: SHA-256 hash of 17 codegen + 89 IR source files - Outputs: [target/codegen/bin, target/codegen/lib] https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
After successful test generation, write a manifest entry for `build:generated_tests` recording the input hash. The hash includes: - gunbc-dag/src/**/*.rs (DAG definitions) - core/ir/src/**/*.rs (IR types) - lib/**/*.rs (library DAG definitions) - Dependency on generated_cli (codegen must run first) This completes Phase 3: both codegen and testgen now update the resource manifest on success, enabling CI to check freshness using manifest-based comparison instead of file existence. https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
Replace brittle file existence check with manifest-based freshness in the CI pipeline's codegen detection. Changes to gunbc-dag/src/ci/ops.rs: - Import resource manifest types - Add ManifestCheckResult enum for check outcomes - check_codegen_manifest_freshness(): Compare stored vs computed hash - compute_codegen_input_hash(): Hash codegen inputs (matches codegen main.rs) - execute_parse_codegen_exists(): Two-tier freshness check: 1. Primary: manifest-based hash comparison 2. Fallback: file existence (for bootstrap when no manifest) This fixes the TODO/URGENT_codegen_upsert.md issue - CI now properly detects when codegen inputs have changed, not just file existence. https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c883a20d54
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Add `--mode=verify|ensure` flag to the CI tool that controls how stale
resources are handled:
- `--mode=ensure` (default): Run codegen if stale/missing (dev-friendly)
- `--mode=verify`: Fail immediately if codegen is stale/missing (CI strict)
Changes:
- gunbc-dag/src/bin/ci.rs:
- Parse --mode flag and set GUNBC_EXEC_MODE environment variable
- Print resource_mode in header
- Updated help text with examples
- gunbc-dag/src/ci/ops.rs:
- Import ExecMode
- get_exec_mode_from_env(): Read mode from environment
- execute_parse_codegen_exists(): In verify mode, return error for
stale/missing instead of triggering codegen
This enables strict CI mode where codegen must be committed, while
preserving the default dev-friendly behavior of auto-regeneration.
https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
Mark completed phases in design doc: - Phase 3: Manifest Integration ✓ - Phase 4: CI Integration ✓ - Phase 5: ExecMode Integration ✓ - Phase 6: Marked as deferred (infrastructure ready) - Phase 8: Cleanup ✓ Add resolved items section to TODO_hacks documenting the fix for the brittle file existence check, now replaced with manifest-based freshness checking. https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
Document patterns identified via codebase scan that could benefit from the unified resource model: - High priority: Makefile/gitignore generation, deps.toml tracking - Medium priority: Per-tool test tracking, ToolHandle unification - Low priority: Per-test-file tracking, coverage artifacts Includes recommended extension order based on impact vs complexity. https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
The resource manifest and hash computation are infrastructure code (like codegen/testgen) that need direct filesystem access for: - Reading source files to compute content hashes - Loading/saving the manifest file Added #[allow(clippy::disallowed_methods)] to: - ContentHash::from_file - HashBuilder::update_file - ResourceManifest::load - ResourceManifest::save - manifest tests module https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
The disallowed_methods lint (no std::fs) applies crate-wide but the architectural boundary (DAG runtime vs build infrastructure) doesn't match crate boundaries. This causes proliferation of #[allow] pragmas. Solution: Extract hash.rs and manifest.rs into a new gunbc-infra crate with its own clippy.toml that doesn't have the disallowed_methods rule. This makes the lint boundary match the architectural boundary. https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
- design-unified-resource-model.md: Updated status to reflect phases 1-5 complete, updated TODONE references - design-resource-acquisition.md: Added status section reflecting phases 1-3 complete, remaining work tracked in unified model No items needed to move to TODONE - all active TODO docs have open work. https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
Correctness fixes: 1. HashBuilder now includes path + delimiter + length to prevent boundary collisions (e.g., A="ab",B="c" vs A="a",B="bc") 2. Glob errors propagated instead of silently dropped 3. CI "Fresh" check now verifies output files exist (handles case where manifest restored from cache but files weren't) 4. Manifest load errors return Error, not Missing (corrupted JSON no longer falls back to file existence) 5. Verify mode is strict: missing manifest = fail (can't prove freshness without it) Design issues documented in TODO_hacks for future cleanup: - #6: Duplicate codegen hash logic (fix with gunbc-infra) - #8: GUNBC_EXEC_MODE env var bridge - #9: ResourceHandle forgeable - #10: ManagedResource::compute_key lacks manifest param - #11: SimpleResource silent empty hash - #12: check_state computes keys when entry missing https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
New architecture-debt.md provides unified view of all debt: - Root cause: missing infrastructure layer (gunbc-infra) - Secondary issue: naive hashing strategy (O(n) per check) - Tiered execution plan: infra extraction → perf fixes → extensions Updated design-resource-performance.md with key insight: - Current design hashes everything on every check (wrong) - Solution: mtime fast path like Make (1976) - Better: git-aware freshness in git repos The gunbc-infra extraction is the force multiplier that unblocks most other cleanups. Should be done before adding more features. https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
Updated architecture-debt.md with actual file:line references showing: Issue 1: 20+ #[allow(clippy::disallowed_methods)] pragmas - 15 in core/ir/src/ alone (should be I/O-free crate) - 7 in codegen/testgen binaries Issue 2: Duplicate compute_codegen_input_hash() - core/codegen/src/main.rs:790-813 - gunbc-dag/src/ci/ops.rs:337-355 - Nearly identical, can't share due to dep direction Issue 3: String-based function refs (circular dep workaround) - CliBinaryDef.graph_builder is a String like "build_gist_graph" - testgen.rs has hardcoded function calls - Renaming a builder silently breaks at runtime Issue 4: ~400 file reads per CI run - codegen hashes ~100 files - testgen hashes ~200 files - ci/ops.rs hashes same ~100 files again - Should be 0 with mtime fast path https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
- testgen: Return error when codegen manifest missing instead of using "missing" sentinel string (silent hash collision risk) - codegen/testgen: Improve manifest write error messages with actionable context for CI failures - Document RUSTC_VERSION env var as known limitation rather than adding another Command::new bypass of transport abstraction https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
- Glob hash already includes paths (update_file hashes path + content) - Renaming a.rs to b.rs will produce different hash - no bug here - SimpleResource::compute_key() is test-only placeholder, not used in production (documented in TODO_hacks #11) - Apply clippy auto-fixes: remove needless borrows, use io::Error::other https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
- Mark architecture-debt.md as URGENT priority for infra extraction - Document Issue 5: Non-uniform hashing (SHA-256 vs DefaultHasher) - Add hash/staleness call sites inventory showing: - Duplicate compute_codegen_input_hash() in codegen and ci/ops - Different hash algorithm in lib/blob (DefaultHasher, 64-bit) - testgen depends on codegen key for dependency tracking - Post-infra plan: single hash source, unified algorithm policy https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
- Document hash_finding_id boundary collision bug (lib/review/src/lib.rs:523) Same pattern as the HashBuilder bug we fixed: colon separator allows collisions like check_id="a", issue_key="b:c" vs check_id="a:b", issue_key="c" - Document recent commit c3d753c adding another #[allow] exemption with comment "same exemption as gunbc-codegen" — showing the pattern continues - Expand Issue 5 to cover both algorithm differences AND encoding bugs - Add hash_finding_id to call sites inventory Root cause confirmed: no central hashing utility means bugs get fixed in one place but the same pattern exists elsewhere. https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
Resolve conflict in gunbc-dag/src/ci/ops.rs: - Keep both ResourceId and CODEGEN_BIN_DIR imports - Use CODEGEN_BIN_DIR constant for codegen path (from main) - Keep fallback comment (from HEAD) https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
This was referenced May 9, 2026
briansrls
added a commit
that referenced
this pull request
May 10, 2026
…SING Two valid findings from codex schedule review on sha f6a3a13 (review id 4259176210): #5 — T-Bridge-Retirement count conflated PR-merge with gate-PASSING: Cell said "3/5 retired" but §1.8 truth: #32 PASSING, #33 DECLARED, #34 DECLARED, #35 PASSING. PR #2449 + PR #2459 ARE merged but the gates haven't been promoted from DECLARED → PASSING (separate status drift sweep step, e.g., per PR #2399 cadence). Reframed cell to distinguish PR-merge evidence from canonical §1.8 status: 2/5 gate-PASSING (#32 + #35), 2/5 PR-merged-pending-promotion (#33 + #34), plus SourceSpan.file participation (Substrate-owned hand-Rust audit sites; not in numbered §1.8) + residual semantic patching (`bridge_exact_string_semantic_patching_residual` Open per #35 close-criterion). #6 — T-Free-Consequences over-claim on PR-merge: Cell said "gate #43 MERGED" but §1.8 #43 still DECLARED (PR #2495 is evidence toward promotion, not the promotion event). Same fix: reframe as PR-merge evidence accruing toward §1.8 gate promotion; canonical status authoritative. Compile-note also reframed: explicitly distinguishes PR-merge evidence from §1.8 gate-PASSING promotion. PR-merge events are listed as evidence accruing toward promotion; canonical gate status varies per §1.8. Common root: future Monday compiles must mechanically reconcile each "landed/retired" claim against §1.8 status, NOT PR-merge events. Discipline recorded in feedback_pm_compile_audits_pre_existing_errors (updated to include PR-merge-vs-gate-promotion distinction). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
May 10, 2026
…2583) * docs(r3): §3 lane-status weekly compile (2026-05-11 Monday cadence) PM-derived compile per §9.1 weekly cadence. Updates Status / Current dispatch / Blocker / ETA-to-close columns based on observable PR merge data + worker session activity + silent-ram-834 status report at gunbc#828 c#4414611117. Lanes with substantial movement this cycle: - T-LensProducer-Retirement: gate #5 lens_apply.rs in flight (valiant-otter-715) - T-Numeric-Construction: u128 mirror sync MERGED #2526; gates #17 + #20 active - T-Free-Consequences-Demonstration: 6 gates merged (#10/#33/#37/#40/#43/#72) - T-Bridge-Retirement: 2/5 sub-bridges retired (PR #2459 + #2449) - T-Lens-Behavioral-Parity: #73 + #78 active under Substrate Mgr - T-Debt-Paydown (standing): Mgr re-spawn (gentle-newt-665 → silent-ram-834); Phase 3 fleet 8/10 closed/absorbed; orphan PR #2503 closed - T-Omni-Shape-B: gate #25 salvage path under PB Mgr; #26/#27 mis-parented Lanes with no observable change this cycle: - T-V-L4, T-V-L5-Corpus, T-FixedPoint, T-Anthropic-Wire, T-V2-Retirement, T-Tests-As-Data-Completeness — substrate work continues but no clear gate-level deltas surfaced Mgr canvas refreshes remain formal authority per §3 framing; lane-owning Mgrs may correct/override any PM-derived cell. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(r3): address codex BLOCKING findings on PR #2583 §3 compile 3 valid findings from codex review: 1. T-Lens-Behavioral-Parity status was "RED→YELLOW (PM-derived; Mgr ratification welcome)" — created parallel-representation hedge in a single-authority cell (INVARIANTS P2 violation; per feedback_parallel_representation_debt). Resolved: commit fully to YELLOW as the PM-compiled value (the §3 disclaimer note covers Mgr override authority). The hedge in the cell was worst-of-both-worlds. 2. PM compile note said T-Tests-As-Data-Completeness had "no observable change this cycle" but the table cell records PR #2287 (Verification V1 TC1 first slice) MERGED 2026-05-10. Self-contradicting. Resolved: moved T-Tests-As-Data-Completeness to "lanes with substantial movement" list. Also added T-Anthropic-Wire (PR #2506), T-V2-Retirement (PR #2334), T-V-L7 (gate #10 / PR #2394), T-Tier3-Dissolution (clever-bear-180 active), T-Lens-Application-Surface (crisp-raven-202 active) to the movement list — all had cell-level deltas in the table that the compile note had missed. 3. PR #2394 merge date inconsistency: T-V-L7 cell said "2026-05-09", T-Free-Consequences cell said "2026-05-10". Verified merge timestamp 2026-05-10T00:26:42Z UTC; corrected T-V-L7 cell to 2026-05-10. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(r3): fix T-LensProducer-Retirement blocker (codex BLOCKING #2 on PR #2583) Pre-existing error in §3 cell that prior PM compile preserved instead of correcting. The original cell named "T-FixedPoint + R2-Evaluator" as T-LensProducer-Retirement's blocker, but per the canonical sequence: - r3-structure.md:357: critical path is `R2-Evaluator → T-LensProducer- Retirement → T-FixedPoint → T-V2-Retirement` - r3-program-plan.md:360-363: "T-LensProducer-Retirement comes BEFORE T-FixedPoint, not after; T-FixedPoint depends on SG-0 zero from T-LensProducer" T-LensProducer-Retirement coming AFTER T-FixedPoint creates a circular dependency in the weekly snapshot. Corrected to use the canonical R2-close-dependency from r3-structure.md §"Lane structure": R2-Evaluator (interpreter-as-data; LANDED) + PB-1 generated bin-shim pattern + R2-T-Ground-Lifetime-Analyzer a/b/c basic cases. Also added warm-crab-600's gate #7 work-in-flight signal (regen_lens.rs retirement; the 3rd sub-gate of T-LensProducer-Retirement) per latest subtree status digest. All 3 sub-gates now in flight: #5 valiant-otter- 715, #6 same-cascade, #7 warm-crab-600. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(r3): address codex BLOCKING #2/#3/#4 — single-authority reconciliation per §1.8 Three valid cell-level findings from codex schedule review on sha 1d95e61. All caught the same root issue: §3 cells didn't reconcile against §1.8 ledger + r3-structure.md canonical authority before landing. #2 — T-Numeric-Construction blocker (line 424): Cell said "Float migration + Real/base-carrier convention HELD on proud-raven-495 G2 Phase 2 Substrate S8 ApproximateField<F>" but §1.8 #18 + #24 explicitly say "CONSUMER_LANDED + PASSING for Grounding G2 primitive rows (2026-05-10, PR #2570 squash b96a51a)" — the work landed. Updated cell to: PR #2570 closes the prior HELD; remaining blocker is broader Real<N> emission demonstrations under S9/Shape-A follow-ons per §1.8 #18 close-criterion. #3 — T-Bridge-Retirement count (line 427): Cell said 3 remaining sub-bridges including mark_bootstrap_secret_ nominal_opacity, but §1.8 #32 PASSING + §2.3 explicitly says that bridge is closed. Corrected count: 3/5 sub-bridges retired (gate #32 prior-cycle Secret nominal-opacity + gate #33 this cycle canonical lens + include_str this cycle), 2 remaining (SourceSpan.file participation + patch_lower_helpers residual). #4 — T-Free-Consequences-Demonstration over-attribution (line 430): Cell credited gates #10/#33/#37/#40/#72 to T-Free, but §1.8 assigns those to other lanes: - #10 → T-V-L4-L7-Direct - #33 → T-Bridge-Retirement - #37 + #40 → T-CostLens-Composition - #72 → T-E-P-Producer-Broadening T-Free's canonical demo gate range is #43-#52. Only #43 (auto_parallelism_independent_binds_emit_parallel) MERGED this cycle for T-Free. Updated cell + compile-note to credit each landing only to its canonical-lane row. Compile-note also reconciled per the same §1.8 single-authority pass: T-CostLens-Composition + T-E-P-Producer-Broadening now credited their own gates instead of attributing them to T-Free. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(r3): address codex BLOCKING #5/#6 — PR-merge evidence ≠ gate-PASSING Two valid findings from codex schedule review on sha f6a3a13 (review id 4259176210): #5 — T-Bridge-Retirement count conflated PR-merge with gate-PASSING: Cell said "3/5 retired" but §1.8 truth: #32 PASSING, #33 DECLARED, #34 DECLARED, #35 PASSING. PR #2449 + PR #2459 ARE merged but the gates haven't been promoted from DECLARED → PASSING (separate status drift sweep step, e.g., per PR #2399 cadence). Reframed cell to distinguish PR-merge evidence from canonical §1.8 status: 2/5 gate-PASSING (#32 + #35), 2/5 PR-merged-pending-promotion (#33 + #34), plus SourceSpan.file participation (Substrate-owned hand-Rust audit sites; not in numbered §1.8) + residual semantic patching (`bridge_exact_string_semantic_patching_residual` Open per #35 close-criterion). #6 — T-Free-Consequences over-claim on PR-merge: Cell said "gate #43 MERGED" but §1.8 #43 still DECLARED (PR #2495 is evidence toward promotion, not the promotion event). Same fix: reframe as PR-merge evidence accruing toward §1.8 gate promotion; canonical status authoritative. Compile-note also reframed: explicitly distinguishes PR-merge evidence from §1.8 gate-PASSING promotion. PR-merge events are listed as evidence accruing toward promotion; canonical gate status varies per §1.8. Common root: future Monday compiles must mechanically reconcile each "landed/retired" claim against §1.8 status, NOT PR-merge events. Discipline recorded in feedback_pm_compile_audits_pre_existing_errors (updated to include PR-merge-vs-gate-promotion distinction). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This was referenced May 10, 2026
This was referenced May 10, 2026
briansrls
added a commit
that referenced
this pull request
May 10, 2026
Promotes 4 §1.8 rows with PR-evidence on main. PB Mgr post-merge ledger-receipt sync per Director ratification at gunbc#828 (c#4415884211; same pattern as PR #2399). Promotions: - #6 lens_testgen_dot_rs_retired DECLARED -> CONSUMER_LANDED + PASSING (PR #2392 producer + PR #2594 regression-guard; lens_testgen.rs absent on disk; consumer-side ratchet test landed) - #33 bridge_canonical_lens_name_dispatch_retired DECLARED -> CONSUMER_LANDED (PR #2449) - #34 bridge_include_str_side_channels_retired DECLARED -> CONSUMER_LANDED (slice scope) (PR #2459 pipeline.dag slice; standalone closure brief #1976 STOP-BLOCKED on Substrate T1) - #66 lens_producer_retirement_executable_witness Notes-update only (PR #2595 substrate-impl landed: TestRunner executes .dag PB census claim and reports residual; closure-receipt remains F3-DEFERRED per PB Mgr disposition) Excluded (out of charter): - #31 -> Substrate (#2068) - #36 -> Verification (#2075) Excluded (T-V2-Retirement HELD on PM-authored S-1 brief #1974): - #41 / #42 / #60 / #71 Pre-authored brief at docs/briefs/r3-pb-status-drift-sweep-post-tlp.md covers the post-T-LP cascade wave (G5/G7/G8). Closes PB Mgr drift-sweep obligation for already-merged evidence; G5/G7/G8 remain queued per pre-authored brief. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
May 10, 2026
…2631) * docs(audit): land R-3 + R-7 ratifications (T-Tier3 perf budget) §5.1 designation in canonical-bench-host-decision-matrix: Option A ubicloud-standard-2 ratified 2026-05-08 per PB Manager (warm-dove-618); Director ratification at gunbc#828 c#4403509523. §2 capture procedure: multi-run discipline addendum — N=5 preferred, median-of-medians for median_ns, max-p99-across-runs for p99_ns, per-run intermediates committed alongside final tier3_baseline.json. Both lines unblock #2204 slice dispatch (Substrate-side PerfWithinBaseline variant + PerfBaselineMeasurement carrier); PB consumer slice queues post-#2204 land. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * PB Item 5 brief — encode substrate disposition (#2068 P1 RATIFIED) Substrate Mgr (warm-wolf-698) ratified §7.3 disposition at gunbc#2068 c#4411574142: shape (b) CensusSubsetCount filter with closed predicate BinShimFilesSubsetPredicate, mirroring existing LensProducerFilesSubsetPredicate precedent. Per feedback_strict_mirror_vs_novel_substrate_fact, strict-mirror ratifies directly (no canvas needed). Updates r3-pb-binshim-retirement-worker.md: - New §"Substrate landings (locked shape)" with the 4 required artifacts (substrate marker type + value, runtime predicate body, dispatch branch). - §7.3 acceptance now authorable; locked TestClaim shape recorded. - Dispatch precondition (5): unauthorable → RESOLVED. - STOP condition: §7.3 disposition not-yet-live → drift-detection. - Status header: PROPOSAL → READY-FOR-DISPATCH posture (pending only the standard R2/R2-Evaluator close signal; both Item-4 sub-gates met via PR #2282 / #2227 close). Bin-shim file inventory at main 5a13ed8: 9 files in src/v3/compiler/src/bin/; closure when CensusSubsetCount predicate count == 0. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: R3 PB Mgr — lane through R3 close * brief: clarify §7.3 TestClaim is zero-only (not schedule-bound) Addresses non-blocking improvement on PR #2334 (codex review sha=68977425): the prior wording called CensusSubsetCount a schedule-bound gate, but the runtime predicate (test_runner.rs:3290-3296) is zero-only — Pass iff count==0. Interim per-PR shrink receipts are PR-level milestones outside this TestClaim, not TestClaim verdicts. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * brief: reconcile §"Substrate landings" with Non-goals (PB strict-mirror authoring authorized post-#2068) Addresses non-blocking improvement on PR #2334 (codex review sha=363cf799): the new §"Substrate landings (locked shape)" worker-owned list contradicted the unchanged "out of scope" entries that still said PB lane does not author §7.3 substrate shape. Resolution: per #2068 c#4411574142 ratification + feedback_strict_mirror_vs_ novel_substrate_fact, strict-mirror declarations (mirroring the existing LensProducerFilesSubsetPredicate precedent) are PB-lane-authorable. The non-goal still applies to *novel* shape (extra fields, alternative coproducts) which would re-escalate to Substrate Mgr. Updates: - "PB does not own and must not edit" entry (line 29): clarifies shape question is Substrate-territory but strict-mirror authoring is authorized. - Non-goals (line 155): same reconciliation; novel shape still gates back to Substrate Mgr. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * PB Item 5 follow-on brief — batch retirement for 8 remaining bin-shims Director re-task at gunbc#828 c#4413892216 Task A: author per-shim retirement worker briefs for the 9 bin-shims; 1 covered by gate #7 (warm-crab-600 working regen_lens.rs); 8 unscoped (emit_method_template_projection, r1c_e_emit_gates, regen_bootstrap, regen_parse, regen_parse_tables, regen_tokenize, regen_v3, self_host_fixed_point). This brief governs the 8-shim batch follow-on against the canonical r3-pb-binshim-retirement-worker.md template. Status PROPOSAL — dispatch-gated on: - smart-tern-649 Stage A landing (BinShimFilesSubsetPredicate carriers + runtime predicate) - warm-crab-600 gate #7 first-cut precedent on main Three staging shapes documented (mega-PR / serial-per-shim / batched-2-3); PB Mgr leans batched-by-regen-family. Worker chooses at dispatch. STOP-AND-PING conditions enumerated (substrate-carrier absent / carrier shape pressure / emit-pattern divergence / substrate-grep mismatch). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix-forward (PR #2471 codex REQUEST_CHANGES) Two findings addressed: 1. Carrier-shape mismatch (line 43): brief template said `name:` but the locked BinShim carrier per design-pb-runtime-interpreter.md:200-204 uses `entrypoint_name`, `description`, `entry`. P2 single-authority violation would have routed workers against wrong shape. Fixed: template now matches locked shape verbatim with explicit no-additional-fields clause. 2. Dispatch-gate dilution (lines 33, 98): brief reduced operative dispatch gate to "Stage A landing + gate #7 precedent" but parent brief enumerates 5 preconditions (R2 close + R2-Evaluator landed + Item 4 sub-gate green + BinShim carrier live + §7.3 disposition). P5 fail-closed violation. Fixed: full readiness prerequisite inherited verbatim from parent brief; gate #7 precedent demoted to implementation-pattern reference (not gate). Worker dispatch posture updated to require all 5 preconditions verified on main at dispatch time per feedback_substrate_grep_before_authoring. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: R3 PB Mgr — lane through R3 close * docs(r3): §1.8 ledger Status drift sweep — post-T-LP / T-Bridge wave Promotes 4 §1.8 rows with PR-evidence on main. PB Mgr post-merge ledger-receipt sync per Director ratification at gunbc#828 (c#4415884211; same pattern as PR #2399). Promotions: - #6 lens_testgen_dot_rs_retired DECLARED -> CONSUMER_LANDED + PASSING (PR #2392 producer + PR #2594 regression-guard; lens_testgen.rs absent on disk; consumer-side ratchet test landed) - #33 bridge_canonical_lens_name_dispatch_retired DECLARED -> CONSUMER_LANDED (PR #2449) - #34 bridge_include_str_side_channels_retired DECLARED -> CONSUMER_LANDED (slice scope) (PR #2459 pipeline.dag slice; standalone closure brief #1976 STOP-BLOCKED on Substrate T1) - #66 lens_producer_retirement_executable_witness Notes-update only (PR #2595 substrate-impl landed: TestRunner executes .dag PB census claim and reports residual; closure-receipt remains F3-DEFERRED per PB Mgr disposition) Excluded (out of charter): - #31 -> Substrate (#2068) - #36 -> Verification (#2075) Excluded (T-V2-Retirement HELD on PM-authored S-1 brief #1974): - #41 / #42 / #60 / #71 Pre-authored brief at docs/briefs/r3-pb-status-drift-sweep-post-tlp.md covers the post-T-LP cascade wave (G5/G7/G8). Closes PB Mgr drift-sweep obligation for already-merged evidence; G5/G7/G8 remain queued per pre-authored brief. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): fix gate #64 → #66 mislabel in drift-sweep brief Per cursor/composer-2 review on PR #2631: brief table + dispatch-trigger parenthetical labeled lens_producer_retirement_executable_witness as gate #64. Authoritative §1.8 row is #66; #64 is substrate_gap_reflection_closure_closed (separate predicate). Aligns brief with r3-program-plan.md §1.8 row identity per INVARIANTS.md P1 (single authoritative facts). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(r3): row #66 DECLARED → CONSUMER_LANDED per §1.7 taxonomy Per codex/codex-default review on PR #2631 (REQUEST_CHANGES, review 9150): leaving row #66 at DECLARED while the Notes cell describes an executable consumer that runs through TestRunner contradicts the §1.7 status taxonomy and INVARIANTS P2 single-authority discipline. Promoting #66 to CONSUMER_LANDED with explicit PASSING gate on residual = 0 (cascades from T-LensProducer-Retirement gates #5 + #6 + #7). The F3 deferral is on PASSING, not CONSUMER_LANDED; the executable receipt src/v3/compiler/tests/integration/r3_lens_producer_retirement_executable_witness_test.rs already exists and runs the .dag PB census claim through TestRunner. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
May 10, 2026
…2657) acceptance per r3-structure.md:184 Reverts row #66 lens_producer_retirement_executable_witness in docs/r3-program-plan.md from CONSUMER_LANDED back to DECLARED with explicit canonical-acceptance framing. Per briansrls + codex/codex-default BLOCKING reviews on merged PR #2631 (post-merge inline + main review at 2026-05-10T20:15Z): the lens_producer_files_remaining census check shipped via PR #2595 is the r3-structure.md:184 "near-term demo = retirement state-check + doc receipts" placeholder, NOT the canonical demonstration consumer. The canonical Pass-condition is "lens_apply reflection routes via PB-Runtime on representative lens program" with execution-ready witness DEFERRED to Row-4 equivalence receipt + Item 4 landing per docs/design-pb-runtime-interpreter.md §5.1. Promoting row #66 to CONSUMER_LANDED on the basis of substrate plumbing dilutes the demonstration gate against INVARIANTS.md P2 single-authority discipline. Status re-promotes only when Row-4 + Item 4 receipts land. Also removes #66 from the post-T-LP drift-sweep brief's promotion set with explicit exclusion-by-canonical-acceptance-scope rationale. Other promotions in PR #2631 (#6 PASSING, #33 / #34 CONSUMER_LANDED) stand — those rows have canonical-fit consumers landed. Refs: PR #2631 #issuecomment thread (briansrls inline reviews + codex review at sha 18d279c); r3-structure.md:184; design-pb-runtime -interpreter.md §5.1. Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
May 14, 2026
briansrls
added a commit
that referenced
this pull request
May 14, 2026
briansrls
added a commit
that referenced
this pull request
May 14, 2026
briansrls
added a commit
that referenced
this pull request
May 15, 2026
* retire pipeline include_str side channel ratchet * WIP: R3 gate #34: bridge_include_str_side_channels_retired (T-Bridge-Retireme * clean up pipeline include_str scanner * document pipeline include_str sentinels * Harden include_str pipeline ratchet scanner * Handle lifetimes in pipeline include ratchet * WIP: R3 gate #34: bridge_include_str_side_channels_retired (T-Bridge-Retireme * WIP: R3 gate #34: bridge_include_str_side_channels_retired (T-Bridge-Retireme * Handle raw string fragments in pipeline include ratchet * Handle char fragments in pipeline include ratchet * Decode escapes in pipeline include ratchet
briansrls
added a commit
that referenced
this pull request
May 21, 2026
briansrls
added a commit
that referenced
this pull request
May 21, 2026
briansrls
added a commit
that referenced
this pull request
May 22, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR introduces a unified resource acquisition model that consolidates multiple ad-hoc patterns (tool installation, code generation, test generation, formatting) into a single abstraction. Resources are now managed through explicit freshness keys derived from declared inputs, replacing brittle file-existence checks and manual dependency wiring.
Key Changes
Core Resource Abstraction
ManagedResourcetrait (core/ir/src/resource/managed.rs): Unifies all acquirable things (tools, build artifacts, etc.) with a consistent Check → Create → Resolve patternResourceHandle<R>struct: Unified proof of acquisition that flows through DAG edges, replacing separate patterns for tools vs build resourcesResourceDefandInputPattern: Explicit declaration of resource inputs (globs, dependencies, environment variables) that determine freshness keysResourceStateenum: Clear state transitions (Missing, Fresh, Stale, Error)Manifest System
ResourceManifestandManifestEntry: Persistent tracking of resource freshness with content hashesContentHashandHashBuilder: SHA-256 based freshness keys computed from declared inputstarget/.resource-manifest.jsonwith atomic write semanticsCodegen Integration
core/codegen/src/main.rsto compute and record input hashes after successful codegenDesign Documentation
design-unified-resource-model.md: Comprehensive design consolidating URGENT_codegen_upsert.md, design-build-resource-chain.md, and related hacksdesign-resource-performance.md: Performance considerations and optimization roadmap (deferred)design-resource-acquisition.mdwith cross-references to unified modelDependency Management
sha2,hex, andglobcrates to support hash computation and file pattern matchingNotable Implementation Details
Hash Scope is Derived: No configuration needed — hash scope is automatically derived from declared
InputPatternentries. This eliminates the "narrow vs wide" configuration choice.Staleness Propagates Naturally: When resource A becomes stale, any resource B that depends on A (via
InputPattern::Resource) automatically becomes stale because B's hash includes A's key.Mode as Executor Context:
ExecMode(Verify/Ensure) is ambient context from the executor, not DAG structure. The same DAG runs in both CI (fail if stale) and dev (regenerate if stale) modes.Safe/Slow First: Conservative implementation prioritizes correctness. Performance optimizations (mtime-based caching, glob result caching) are documented in
design-resource-performance.mdfor future work.Manifest Atomicity: Manifest updates use temp-file-then-rename pattern to ensure consistency even if the process crashes.
Addresses
target/codegen/bin/deps/main.rshack)extra_deps,fix_deps,PrepLevel)Future Work
This PR establishes the foundation. Subsequent phases will:
--mode=verify|ensureflag to build tools (Phase 5)ToolHandleto useResourceHandle<ToolResource>(Phase 7)https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c