Skip to content

Introduce unified resource model with manifest-based freshness tracking - #34

Merged
briansrls merged 21 commits into
mainfrom
claude/urgent-todos-XthMR
Feb 5, 2026
Merged

briansrls merged 21 commits into
mainfrom
claude/urgent-todos-XthMR

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Summary

This PR introduces a unified resource acquisition model that consolidates multiple ad-hoc patterns (tool installation, code generation, test generation, formatting) into a single abstraction. Resources are now managed through explicit freshness keys derived from declared inputs, replacing brittle file-existence checks and manual dependency wiring.

Key Changes

Core Resource Abstraction

  • New ManagedResource trait (core/ir/src/resource/managed.rs): Unifies all acquirable things (tools, build artifacts, etc.) with a consistent Check → Create → Resolve pattern
  • ResourceHandle<R> struct: Unified proof of acquisition that flows through DAG edges, replacing separate patterns for tools vs build resources
  • ResourceDef and InputPattern: Explicit declaration of resource inputs (globs, dependencies, environment variables) that determine freshness keys
  • ResourceState enum: Clear state transitions (Missing, Fresh, Stale, Error)

Manifest System

  • ResourceManifest and ManifestEntry: Persistent tracking of resource freshness with content hashes
  • ContentHash and HashBuilder: SHA-256 based freshness keys computed from declared inputs
  • Manifest stored at target/.resource-manifest.json with atomic write semantics

Codegen Integration

  • Updated core/codegen/src/main.rs to compute and record input hashes after successful codegen
  • Manifest entries track which files contributed to each resource's freshness
  • Non-fatal manifest write failures don't block codegen success

Design Documentation

  • design-unified-resource-model.md: Comprehensive design consolidating URGENT_codegen_upsert.md, design-build-resource-chain.md, and related hacks
  • design-resource-performance.md: Performance considerations and optimization roadmap (deferred)
  • Updated design-resource-acquisition.md with cross-references to unified model

Dependency Management

  • Added sha2, hex, and glob crates to support hash computation and file pattern matching
  • These enable the core freshness checking without external tools

Notable Implementation Details

  1. Hash Scope is Derived: No configuration needed — hash scope is automatically derived from declared InputPattern entries. This eliminates the "narrow vs wide" configuration choice.

  2. Staleness Propagates Naturally: When resource A becomes stale, any resource B that depends on A (via InputPattern::Resource) automatically becomes stale because B's hash includes A's key.

  3. Mode as Executor Context: ExecMode (Verify/Ensure) is ambient context from the executor, not DAG structure. The same DAG runs in both CI (fail if stale) and dev (regenerate if stale) modes.

  4. Safe/Slow First: Conservative implementation prioritizes correctness. Performance optimizations (mtime-based caching, glob result caching) are documented in design-resource-performance.md for future work.

  5. Manifest Atomicity: Manifest updates use temp-file-then-rename pattern to ensure consistency even if the process crashes.

Addresses

  • Brittle file-existence check in CI (target/codegen/bin/deps/main.rs hack)
  • Manual dependency wiring in Makefile (extra_deps, fix_deps, PrepLevel)
  • Duality of testgen/testgen-check and fmt/fmt-fix targets
  • No staleness detection for build artifacts
  • Hardcoded dependency strings not verified at compile time

Future Work

This PR establishes the foundation. Subsequent phases will:

  • Integrate manifest checks into CI graph (Phase 4)
  • Add --mode=verify|ensure flag to build tools (Phase 5)
  • Simplify Makefile generation by removing manual wiring (Phase 6)
  • Migrate ToolHandle to use ResourceHandle<ToolResource> (Phase 7)

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c

This commit creates a unified resource model design that consolidates:
- URGENT_codegen_upsert.md (codegen staleness detection)
- design-build-resource-chain.md (build artifact dependencies)
- Related TODO_hacks items (PrepLevel, extra_deps, fix_deps)

Key insight: Tool acquisition (EnvOp → ToolHandle) and build artifact
management follow the SAME upsert pattern (Check → Create → Resolve).
The only difference is how "freshness" is determined:
- Tools: binary exists on PATH
- Build artifacts: content hash of inputs matches manifest

The new design extends the existing Resource trait with ManagedResource
for freshness checking, and replaces manual dependency wiring with
declarative ResourceContract (provides/needs).

Changes:
- New: TODO/design-unified-resource-model.md (comprehensive design)
- Moved: URGENT_codegen_upsert.md → TODONE (consolidated)
- Moved: design-build-resource-chain.md → TODONE (consolidated)
- Updated: design-resource-acquisition.md (cross-references)
- Updated: TODO_hacks (tracking references)

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
Key design decisions clarified:
- Hash scope derived from declared inputs (like Bazel), not configured
- Staleness propagation falls out of DAG edges via InputPattern::Resource
- Flexible ResourceScope (file, pattern, named) for granularity
- Bootstrap remains special-cased for now
- Unified ResourceHandle<R> for both tools and build artifacts
- ExecMode (Verify/Ensure) is executor context, like DryRun
- DAG is pure; manifest updates are outputs, not side effects

Added detailed 8-phase implementation plan with:
- Estimated scope per phase
- Specific files to create/modify
- Tests required
- Clear before/after examples

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
This implements the core abstractions for the unified resource model
that consolidates tool acquisition and build resources under a single
pattern: Check → Create → Resolve.

New modules in core/ir/src/resource/:
- hash.rs: ContentHash type for SHA-256 freshness keys, plus HashBuilder
  for computing hashes from multiple inputs (files, globs, strings)
- state.rs: ResourceState enum (Fresh/Stale/Missing/Error) and ExecMode
  (Verify/Ensure) for execution context
- def.rs: ResourceDef and InputPattern for declaring resource inputs/outputs.
  Hash scope is derived from declared inputs (like Bazel)
- manifest.rs: ResourceManifest for on-disk storage of freshness keys
  at target/.resource-manifest.json with atomic save/load
- handle.rs: ResourceHandle<R> - unified proof of acquisition that
  flows through DAG edges (unifies ToolHandle and BuildResourceHandle)
- managed.rs: ManagedResource trait with default implementations for
  check_state() and acquire()

Key design decisions:
- Hash scope derived from InputPattern declarations, not configured
- Staleness propagation via InputPattern::Resource dependencies
- Single ResourceHandle<R> type for tools and build resources
- ExecMode as executor context (like DryRun), not DAG structure

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
New: core/ir/src/resource/registry.rs
- ResourceRegistry for holding resource definitions
- Topological sort via resolve() and resolve_all()
- Cycle detection with helpful error messages
- Direct dependency lookup via direct_deps()
- Graph acyclicity check via check_acyclic()

Also added: TODO/design-resource-performance.md
- Documents known performance considerations
- Hash computation on every check (future: mtime caching)
- Glob expansion cost (future: cache results)
- Manifest entry enhancement plan (store file list)
- Optimized freshness check design (fast path/slow path)

Tests include linear chains, diamond dependencies, cycles,
missing resources, and multi-target resolution.

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
After successful codegen, write a manifest entry for `build:generated_cli`
recording the content hash of codegen inputs. This enables CI to check
freshness using the manifest instead of file existence hacks.

Changes to core/codegen/src/main.rs:
- Import resource manifest types from gunbc_ir::resource
- compute_codegen_input_hash(): Hash codegen and IR source files
- write_codegen_manifest(): Write manifest entry with outputs
- update_manifest_after_codegen(): Called after successful codegen
- cmd_codegen and cmd_commit now update manifest on success

The manifest is written to target/.resource-manifest.json with:
- Resource ID: build:generated_cli
- Key: SHA-256 hash of 17 codegen + 89 IR source files
- Outputs: [target/codegen/bin, target/codegen/lib]

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
After successful test generation, write a manifest entry for
`build:generated_tests` recording the input hash. The hash includes:
- gunbc-dag/src/**/*.rs (DAG definitions)
- core/ir/src/**/*.rs (IR types)
- lib/**/*.rs (library DAG definitions)
- Dependency on generated_cli (codegen must run first)

This completes Phase 3: both codegen and testgen now update the
resource manifest on success, enabling CI to check freshness
using manifest-based comparison instead of file existence.

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
Replace brittle file existence check with manifest-based freshness
in the CI pipeline's codegen detection.

Changes to gunbc-dag/src/ci/ops.rs:
- Import resource manifest types
- Add ManifestCheckResult enum for check outcomes
- check_codegen_manifest_freshness(): Compare stored vs computed hash
- compute_codegen_input_hash(): Hash codegen inputs (matches codegen main.rs)
- execute_parse_codegen_exists(): Two-tier freshness check:
  1. Primary: manifest-based hash comparison
  2. Fallback: file existence (for bootstrap when no manifest)

This fixes the TODO/URGENT_codegen_upsert.md issue - CI now properly
detects when codegen inputs have changed, not just file existence.

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c883a20d54

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread core/ir/src/resource/hash.rs
Comment thread core/ir/src/resource/managed.rs
claude added 14 commits February 5, 2026 17:25
Add `--mode=verify|ensure` flag to the CI tool that controls how stale
resources are handled:

- `--mode=ensure` (default): Run codegen if stale/missing (dev-friendly)
- `--mode=verify`: Fail immediately if codegen is stale/missing (CI strict)

Changes:
- gunbc-dag/src/bin/ci.rs:
  - Parse --mode flag and set GUNBC_EXEC_MODE environment variable
  - Print resource_mode in header
  - Updated help text with examples

- gunbc-dag/src/ci/ops.rs:
  - Import ExecMode
  - get_exec_mode_from_env(): Read mode from environment
  - execute_parse_codegen_exists(): In verify mode, return error for
    stale/missing instead of triggering codegen

This enables strict CI mode where codegen must be committed, while
preserving the default dev-friendly behavior of auto-regeneration.

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
Mark completed phases in design doc:
- Phase 3: Manifest Integration ✓
- Phase 4: CI Integration ✓
- Phase 5: ExecMode Integration ✓
- Phase 6: Marked as deferred (infrastructure ready)
- Phase 8: Cleanup ✓

Add resolved items section to TODO_hacks documenting the fix for
the brittle file existence check, now replaced with manifest-based
freshness checking.

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
Document patterns identified via codebase scan that could benefit from
the unified resource model:
- High priority: Makefile/gitignore generation, deps.toml tracking
- Medium priority: Per-tool test tracking, ToolHandle unification
- Low priority: Per-test-file tracking, coverage artifacts

Includes recommended extension order based on impact vs complexity.

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
The resource manifest and hash computation are infrastructure code
(like codegen/testgen) that need direct filesystem access for:
- Reading source files to compute content hashes
- Loading/saving the manifest file

Added #[allow(clippy::disallowed_methods)] to:
- ContentHash::from_file
- HashBuilder::update_file
- ResourceManifest::load
- ResourceManifest::save
- manifest tests module

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
The disallowed_methods lint (no std::fs) applies crate-wide but the
architectural boundary (DAG runtime vs build infrastructure) doesn't
match crate boundaries. This causes proliferation of #[allow] pragmas.

Solution: Extract hash.rs and manifest.rs into a new gunbc-infra crate
with its own clippy.toml that doesn't have the disallowed_methods rule.
This makes the lint boundary match the architectural boundary.

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
- design-unified-resource-model.md: Updated status to reflect phases 1-5
  complete, updated TODONE references
- design-resource-acquisition.md: Added status section reflecting phases
  1-3 complete, remaining work tracked in unified model

No items needed to move to TODONE - all active TODO docs have open work.

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
Correctness fixes:
1. HashBuilder now includes path + delimiter + length to prevent
   boundary collisions (e.g., A="ab",B="c" vs A="a",B="bc")
2. Glob errors propagated instead of silently dropped
3. CI "Fresh" check now verifies output files exist (handles case
   where manifest restored from cache but files weren't)
4. Manifest load errors return Error, not Missing (corrupted JSON
   no longer falls back to file existence)
5. Verify mode is strict: missing manifest = fail (can't prove
   freshness without it)

Design issues documented in TODO_hacks for future cleanup:
- #6: Duplicate codegen hash logic (fix with gunbc-infra)
- #8: GUNBC_EXEC_MODE env var bridge
- #9: ResourceHandle forgeable
- #10: ManagedResource::compute_key lacks manifest param
- #11: SimpleResource silent empty hash
- #12: check_state computes keys when entry missing

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
New architecture-debt.md provides unified view of all debt:
- Root cause: missing infrastructure layer (gunbc-infra)
- Secondary issue: naive hashing strategy (O(n) per check)
- Tiered execution plan: infra extraction → perf fixes → extensions

Updated design-resource-performance.md with key insight:
- Current design hashes everything on every check (wrong)
- Solution: mtime fast path like Make (1976)
- Better: git-aware freshness in git repos

The gunbc-infra extraction is the force multiplier that unblocks
most other cleanups. Should be done before adding more features.

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
Updated architecture-debt.md with actual file:line references showing:

Issue 1: 20+ #[allow(clippy::disallowed_methods)] pragmas
- 15 in core/ir/src/ alone (should be I/O-free crate)
- 7 in codegen/testgen binaries

Issue 2: Duplicate compute_codegen_input_hash()
- core/codegen/src/main.rs:790-813
- gunbc-dag/src/ci/ops.rs:337-355
- Nearly identical, can't share due to dep direction

Issue 3: String-based function refs (circular dep workaround)
- CliBinaryDef.graph_builder is a String like "build_gist_graph"
- testgen.rs has hardcoded function calls
- Renaming a builder silently breaks at runtime

Issue 4: ~400 file reads per CI run
- codegen hashes ~100 files
- testgen hashes ~200 files
- ci/ops.rs hashes same ~100 files again
- Should be 0 with mtime fast path

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
- testgen: Return error when codegen manifest missing instead of using
  "missing" sentinel string (silent hash collision risk)
- codegen/testgen: Improve manifest write error messages with actionable
  context for CI failures
- Document RUSTC_VERSION env var as known limitation rather than adding
  another Command::new bypass of transport abstraction

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
- Glob hash already includes paths (update_file hashes path + content)
- Renaming a.rs to b.rs will produce different hash - no bug here
- SimpleResource::compute_key() is test-only placeholder, not used in
  production (documented in TODO_hacks #11)
- Apply clippy auto-fixes: remove needless borrows, use io::Error::other

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
- Mark architecture-debt.md as URGENT priority for infra extraction
- Document Issue 5: Non-uniform hashing (SHA-256 vs DefaultHasher)
- Add hash/staleness call sites inventory showing:
  - Duplicate compute_codegen_input_hash() in codegen and ci/ops
  - Different hash algorithm in lib/blob (DefaultHasher, 64-bit)
  - testgen depends on codegen key for dependency tracking
- Post-infra plan: single hash source, unified algorithm policy

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
- Document hash_finding_id boundary collision bug (lib/review/src/lib.rs:523)
  Same pattern as the HashBuilder bug we fixed: colon separator allows
  collisions like check_id="a", issue_key="b:c" vs check_id="a:b", issue_key="c"
- Document recent commit c3d753c adding another #[allow] exemption with comment
  "same exemption as gunbc-codegen" — showing the pattern continues
- Expand Issue 5 to cover both algorithm differences AND encoding bugs
- Add hash_finding_id to call sites inventory

Root cause confirmed: no central hashing utility means bugs get fixed in one
place but the same pattern exists elsewhere.

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
Resolve conflict in gunbc-dag/src/ci/ops.rs:
- Keep both ResourceId and CODEGEN_BIN_DIR imports
- Use CODEGEN_BIN_DIR constant for codegen path (from main)
- Keep fallback comment (from HEAD)

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
@briansrls
briansrls merged commit d260e50 into main Feb 5, 2026
1 check passed
briansrls added a commit that referenced this pull request May 10, 2026
…SING

Two valid findings from codex schedule review on sha f6a3a13 (review
id 4259176210):

#5 — T-Bridge-Retirement count conflated PR-merge with gate-PASSING:
   Cell said "3/5 retired" but §1.8 truth: #32 PASSING, #33 DECLARED,
   #34 DECLARED, #35 PASSING. PR #2449 + PR #2459 ARE merged but the
   gates haven't been promoted from DECLARED → PASSING (separate status
   drift sweep step, e.g., per PR #2399 cadence). Reframed cell to
   distinguish PR-merge evidence from canonical §1.8 status: 2/5
   gate-PASSING (#32 + #35), 2/5 PR-merged-pending-promotion (#33 + #34),
   plus SourceSpan.file participation (Substrate-owned hand-Rust audit
   sites; not in numbered §1.8) + residual semantic patching
   (`bridge_exact_string_semantic_patching_residual` Open per #35
   close-criterion).

#6 — T-Free-Consequences over-claim on PR-merge:
   Cell said "gate #43 MERGED" but §1.8 #43 still DECLARED (PR #2495 is
   evidence toward promotion, not the promotion event). Same fix:
   reframe as PR-merge evidence accruing toward §1.8 gate promotion;
   canonical status authoritative.

Compile-note also reframed: explicitly distinguishes PR-merge evidence
from §1.8 gate-PASSING promotion. PR-merge events are listed as evidence
accruing toward promotion; canonical gate status varies per §1.8.

Common root: future Monday compiles must mechanically reconcile each
"landed/retired" claim against §1.8 status, NOT PR-merge events.
Discipline recorded in feedback_pm_compile_audits_pre_existing_errors
(updated to include PR-merge-vs-gate-promotion distinction).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 10, 2026
…2583)

* docs(r3): §3 lane-status weekly compile (2026-05-11 Monday cadence)

PM-derived compile per §9.1 weekly cadence. Updates Status / Current
dispatch / Blocker / ETA-to-close columns based on observable PR merge
data + worker session activity + silent-ram-834 status report at
gunbc#828 c#4414611117.

Lanes with substantial movement this cycle:
- T-LensProducer-Retirement: gate #5 lens_apply.rs in flight (valiant-otter-715)
- T-Numeric-Construction: u128 mirror sync MERGED #2526; gates #17 + #20 active
- T-Free-Consequences-Demonstration: 6 gates merged (#10/#33/#37/#40/#43/#72)
- T-Bridge-Retirement: 2/5 sub-bridges retired (PR #2459 + #2449)
- T-Lens-Behavioral-Parity: #73 + #78 active under Substrate Mgr
- T-Debt-Paydown (standing): Mgr re-spawn (gentle-newt-665 → silent-ram-834);
  Phase 3 fleet 8/10 closed/absorbed; orphan PR #2503 closed
- T-Omni-Shape-B: gate #25 salvage path under PB Mgr; #26/#27 mis-parented

Lanes with no observable change this cycle:
- T-V-L4, T-V-L5-Corpus, T-FixedPoint, T-Anthropic-Wire, T-V2-Retirement,
  T-Tests-As-Data-Completeness — substrate work continues but no clear
  gate-level deltas surfaced

Mgr canvas refreshes remain formal authority per §3 framing; lane-owning
Mgrs may correct/override any PM-derived cell.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): address codex BLOCKING findings on PR #2583 §3 compile

3 valid findings from codex review:

1. T-Lens-Behavioral-Parity status was "RED→YELLOW (PM-derived; Mgr
   ratification welcome)" — created parallel-representation hedge in a
   single-authority cell (INVARIANTS P2 violation; per
   feedback_parallel_representation_debt). Resolved: commit fully to
   YELLOW as the PM-compiled value (the §3 disclaimer note covers Mgr
   override authority). The hedge in the cell was worst-of-both-worlds.

2. PM compile note said T-Tests-As-Data-Completeness had "no observable
   change this cycle" but the table cell records PR #2287 (Verification
   V1 TC1 first slice) MERGED 2026-05-10. Self-contradicting. Resolved:
   moved T-Tests-As-Data-Completeness to "lanes with substantial
   movement" list. Also added T-Anthropic-Wire (PR #2506), T-V2-Retirement
   (PR #2334), T-V-L7 (gate #10 / PR #2394), T-Tier3-Dissolution
   (clever-bear-180 active), T-Lens-Application-Surface (crisp-raven-202
   active) to the movement list — all had cell-level deltas in the table
   that the compile note had missed.

3. PR #2394 merge date inconsistency: T-V-L7 cell said "2026-05-09",
   T-Free-Consequences cell said "2026-05-10". Verified merge timestamp
   2026-05-10T00:26:42Z UTC; corrected T-V-L7 cell to 2026-05-10.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): fix T-LensProducer-Retirement blocker (codex BLOCKING #2 on PR #2583)

Pre-existing error in §3 cell that prior PM compile preserved instead of
correcting. The original cell named "T-FixedPoint + R2-Evaluator" as
T-LensProducer-Retirement's blocker, but per the canonical sequence:

- r3-structure.md:357: critical path is `R2-Evaluator → T-LensProducer-
  Retirement → T-FixedPoint → T-V2-Retirement`
- r3-program-plan.md:360-363: "T-LensProducer-Retirement comes BEFORE
  T-FixedPoint, not after; T-FixedPoint depends on SG-0 zero from
  T-LensProducer"

T-LensProducer-Retirement coming AFTER T-FixedPoint creates a circular
dependency in the weekly snapshot. Corrected to use the canonical
R2-close-dependency from r3-structure.md §"Lane structure":
R2-Evaluator (interpreter-as-data; LANDED) + PB-1 generated bin-shim
pattern + R2-T-Ground-Lifetime-Analyzer a/b/c basic cases.

Also added warm-crab-600's gate #7 work-in-flight signal (regen_lens.rs
retirement; the 3rd sub-gate of T-LensProducer-Retirement) per latest
subtree status digest. All 3 sub-gates now in flight: #5 valiant-otter-
715, #6 same-cascade, #7 warm-crab-600.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): address codex BLOCKING #2/#3/#4 — single-authority reconciliation per §1.8

Three valid cell-level findings from codex schedule review on sha 1d95e61.
All caught the same root issue: §3 cells didn't reconcile against §1.8
ledger + r3-structure.md canonical authority before landing.

#2 — T-Numeric-Construction blocker (line 424):
   Cell said "Float migration + Real/base-carrier convention HELD on
   proud-raven-495 G2 Phase 2 Substrate S8 ApproximateField<F>" but
   §1.8 #18 + #24 explicitly say "CONSUMER_LANDED + PASSING for
   Grounding G2 primitive rows (2026-05-10, PR #2570 squash b96a51a)"
   — the work landed. Updated cell to: PR #2570 closes the prior HELD;
   remaining blocker is broader Real<N> emission demonstrations under
   S9/Shape-A follow-ons per §1.8 #18 close-criterion.

#3 — T-Bridge-Retirement count (line 427):
   Cell said 3 remaining sub-bridges including mark_bootstrap_secret_
   nominal_opacity, but §1.8 #32 PASSING + §2.3 explicitly says that
   bridge is closed. Corrected count: 3/5 sub-bridges retired (gate #32
   prior-cycle Secret nominal-opacity + gate #33 this cycle canonical
   lens + include_str this cycle), 2 remaining (SourceSpan.file
   participation + patch_lower_helpers residual).

#4 — T-Free-Consequences-Demonstration over-attribution (line 430):
   Cell credited gates #10/#33/#37/#40/#72 to T-Free, but §1.8 assigns
   those to other lanes:
   - #10 → T-V-L4-L7-Direct
   - #33 → T-Bridge-Retirement
   - #37 + #40 → T-CostLens-Composition
   - #72 → T-E-P-Producer-Broadening
   T-Free's canonical demo gate range is #43-#52. Only #43
   (auto_parallelism_independent_binds_emit_parallel) MERGED this cycle
   for T-Free. Updated cell + compile-note to credit each landing only
   to its canonical-lane row.

Compile-note also reconciled per the same §1.8 single-authority pass:
T-CostLens-Composition + T-E-P-Producer-Broadening now credited their
own gates instead of attributing them to T-Free.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): address codex BLOCKING #5/#6 — PR-merge evidence ≠ gate-PASSING

Two valid findings from codex schedule review on sha f6a3a13 (review
id 4259176210):

#5 — T-Bridge-Retirement count conflated PR-merge with gate-PASSING:
   Cell said "3/5 retired" but §1.8 truth: #32 PASSING, #33 DECLARED,
   #34 DECLARED, #35 PASSING. PR #2449 + PR #2459 ARE merged but the
   gates haven't been promoted from DECLARED → PASSING (separate status
   drift sweep step, e.g., per PR #2399 cadence). Reframed cell to
   distinguish PR-merge evidence from canonical §1.8 status: 2/5
   gate-PASSING (#32 + #35), 2/5 PR-merged-pending-promotion (#33 + #34),
   plus SourceSpan.file participation (Substrate-owned hand-Rust audit
   sites; not in numbered §1.8) + residual semantic patching
   (`bridge_exact_string_semantic_patching_residual` Open per #35
   close-criterion).

#6 — T-Free-Consequences over-claim on PR-merge:
   Cell said "gate #43 MERGED" but §1.8 #43 still DECLARED (PR #2495 is
   evidence toward promotion, not the promotion event). Same fix:
   reframe as PR-merge evidence accruing toward §1.8 gate promotion;
   canonical status authoritative.

Compile-note also reframed: explicitly distinguishes PR-merge evidence
from §1.8 gate-PASSING promotion. PR-merge events are listed as evidence
accruing toward promotion; canonical gate status varies per §1.8.

Common root: future Monday compiles must mechanically reconcile each
"landed/retired" claim against §1.8 status, NOT PR-merge events.
Discipline recorded in feedback_pm_compile_audits_pre_existing_errors
(updated to include PR-merge-vs-gate-promotion distinction).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 10, 2026
Promotes 4 §1.8 rows with PR-evidence on main. PB Mgr post-merge
ledger-receipt sync per Director ratification at gunbc#828
(c#4415884211; same pattern as PR #2399).

Promotions:
- #6  lens_testgen_dot_rs_retired                     DECLARED -> CONSUMER_LANDED + PASSING
       (PR #2392 producer + PR #2594 regression-guard; lens_testgen.rs
        absent on disk; consumer-side ratchet test landed)
- #33 bridge_canonical_lens_name_dispatch_retired     DECLARED -> CONSUMER_LANDED
       (PR #2449)
- #34 bridge_include_str_side_channels_retired        DECLARED -> CONSUMER_LANDED (slice scope)
       (PR #2459 pipeline.dag slice; standalone closure brief #1976
        STOP-BLOCKED on Substrate T1)
- #66 lens_producer_retirement_executable_witness     Notes-update only
       (PR #2595 substrate-impl landed: TestRunner executes .dag PB
        census claim and reports residual; closure-receipt remains
        F3-DEFERRED per PB Mgr disposition)

Excluded (out of charter):
- #31 -> Substrate (#2068)
- #36 -> Verification (#2075)

Excluded (T-V2-Retirement HELD on PM-authored S-1 brief #1974):
- #41 / #42 / #60 / #71

Pre-authored brief at docs/briefs/r3-pb-status-drift-sweep-post-tlp.md
covers the post-T-LP cascade wave (G5/G7/G8).

Closes PB Mgr drift-sweep obligation for already-merged evidence;
G5/G7/G8 remain queued per pre-authored brief.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 10, 2026
…2631)

* docs(audit): land R-3 + R-7 ratifications (T-Tier3 perf budget)

§5.1 designation in canonical-bench-host-decision-matrix: Option A
ubicloud-standard-2 ratified 2026-05-08 per PB Manager (warm-dove-618);
Director ratification at gunbc#828 c#4403509523.

§2 capture procedure: multi-run discipline addendum — N=5 preferred,
median-of-medians for median_ns, max-p99-across-runs for p99_ns,
per-run intermediates committed alongside final tier3_baseline.json.

Both lines unblock #2204 slice dispatch (Substrate-side PerfWithinBaseline
variant + PerfBaselineMeasurement carrier); PB consumer slice queues
post-#2204 land.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* PB Item 5 brief — encode substrate disposition (#2068 P1 RATIFIED)

Substrate Mgr (warm-wolf-698) ratified §7.3 disposition at gunbc#2068
c#4411574142: shape (b) CensusSubsetCount filter with closed predicate
BinShimFilesSubsetPredicate, mirroring existing LensProducerFilesSubsetPredicate
precedent. Per feedback_strict_mirror_vs_novel_substrate_fact, strict-mirror
ratifies directly (no canvas needed).

Updates r3-pb-binshim-retirement-worker.md:
- New §"Substrate landings (locked shape)" with the 4 required artifacts
  (substrate marker type + value, runtime predicate body, dispatch branch).
- §7.3 acceptance now authorable; locked TestClaim shape recorded.
- Dispatch precondition (5): unauthorable → RESOLVED.
- STOP condition: §7.3 disposition not-yet-live → drift-detection.
- Status header: PROPOSAL → READY-FOR-DISPATCH posture (pending only the
  standard R2/R2-Evaluator close signal; both Item-4 sub-gates met via
  PR #2282 / #2227 close).

Bin-shim file inventory at main 5a13ed8: 9 files in src/v3/compiler/src/bin/;
closure when CensusSubsetCount predicate count == 0.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 PB Mgr — lane through R3 close

* brief: clarify §7.3 TestClaim is zero-only (not schedule-bound)

Addresses non-blocking improvement on PR #2334 (codex review sha=68977425):
the prior wording called CensusSubsetCount a schedule-bound gate, but the
runtime predicate (test_runner.rs:3290-3296) is zero-only — Pass iff
count==0. Interim per-PR shrink receipts are PR-level milestones outside
this TestClaim, not TestClaim verdicts.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* brief: reconcile §"Substrate landings" with Non-goals (PB strict-mirror authoring authorized post-#2068)

Addresses non-blocking improvement on PR #2334 (codex review sha=363cf799):
the new §"Substrate landings (locked shape)" worker-owned list contradicted
the unchanged "out of scope" entries that still said PB lane does not author
§7.3 substrate shape.

Resolution: per #2068 c#4411574142 ratification + feedback_strict_mirror_vs_
novel_substrate_fact, strict-mirror declarations (mirroring the existing
LensProducerFilesSubsetPredicate precedent) are PB-lane-authorable. The
non-goal still applies to *novel* shape (extra fields, alternative
coproducts) which would re-escalate to Substrate Mgr.

Updates:
- "PB does not own and must not edit" entry (line 29): clarifies shape
  question is Substrate-territory but strict-mirror authoring is authorized.
- Non-goals (line 155): same reconciliation; novel shape still gates back
  to Substrate Mgr.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* PB Item 5 follow-on brief — batch retirement for 8 remaining bin-shims

Director re-task at gunbc#828 c#4413892216 Task A: author per-shim retirement
worker briefs for the 9 bin-shims; 1 covered by gate #7 (warm-crab-600 working
regen_lens.rs); 8 unscoped (emit_method_template_projection, r1c_e_emit_gates,
regen_bootstrap, regen_parse, regen_parse_tables, regen_tokenize, regen_v3,
self_host_fixed_point).

This brief governs the 8-shim batch follow-on against the canonical
r3-pb-binshim-retirement-worker.md template. Status PROPOSAL —
dispatch-gated on:
- smart-tern-649 Stage A landing (BinShimFilesSubsetPredicate carriers + runtime predicate)
- warm-crab-600 gate #7 first-cut precedent on main

Three staging shapes documented (mega-PR / serial-per-shim / batched-2-3);
PB Mgr leans batched-by-regen-family. Worker chooses at dispatch.

STOP-AND-PING conditions enumerated (substrate-carrier absent / carrier shape
pressure / emit-pattern divergence / substrate-grep mismatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix-forward (PR #2471 codex REQUEST_CHANGES)

Two findings addressed:

1. Carrier-shape mismatch (line 43): brief template said `name:` but the
   locked BinShim carrier per design-pb-runtime-interpreter.md:200-204 uses
   `entrypoint_name`, `description`, `entry`. P2 single-authority violation
   would have routed workers against wrong shape. Fixed: template now
   matches locked shape verbatim with explicit no-additional-fields clause.

2. Dispatch-gate dilution (lines 33, 98): brief reduced operative dispatch
   gate to "Stage A landing + gate #7 precedent" but parent brief enumerates
   5 preconditions (R2 close + R2-Evaluator landed + Item 4 sub-gate green
   + BinShim carrier live + §7.3 disposition). P5 fail-closed violation.
   Fixed: full readiness prerequisite inherited verbatim from parent brief;
   gate #7 precedent demoted to implementation-pattern reference (not gate).

Worker dispatch posture updated to require all 5 preconditions verified
on main at dispatch time per feedback_substrate_grep_before_authoring.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 PB Mgr — lane through R3 close

* docs(r3): §1.8 ledger Status drift sweep — post-T-LP / T-Bridge wave

Promotes 4 §1.8 rows with PR-evidence on main. PB Mgr post-merge
ledger-receipt sync per Director ratification at gunbc#828
(c#4415884211; same pattern as PR #2399).

Promotions:
- #6  lens_testgen_dot_rs_retired                     DECLARED -> CONSUMER_LANDED + PASSING
       (PR #2392 producer + PR #2594 regression-guard; lens_testgen.rs
        absent on disk; consumer-side ratchet test landed)
- #33 bridge_canonical_lens_name_dispatch_retired     DECLARED -> CONSUMER_LANDED
       (PR #2449)
- #34 bridge_include_str_side_channels_retired        DECLARED -> CONSUMER_LANDED (slice scope)
       (PR #2459 pipeline.dag slice; standalone closure brief #1976
        STOP-BLOCKED on Substrate T1)
- #66 lens_producer_retirement_executable_witness     Notes-update only
       (PR #2595 substrate-impl landed: TestRunner executes .dag PB
        census claim and reports residual; closure-receipt remains
        F3-DEFERRED per PB Mgr disposition)

Excluded (out of charter):
- #31 -> Substrate (#2068)
- #36 -> Verification (#2075)

Excluded (T-V2-Retirement HELD on PM-authored S-1 brief #1974):
- #41 / #42 / #60 / #71

Pre-authored brief at docs/briefs/r3-pb-status-drift-sweep-post-tlp.md
covers the post-T-LP cascade wave (G5/G7/G8).

Closes PB Mgr drift-sweep obligation for already-merged evidence;
G5/G7/G8 remain queued per pre-authored brief.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix gate #64 → #66 mislabel in drift-sweep brief

Per cursor/composer-2 review on PR #2631: brief table + dispatch-trigger
parenthetical labeled lens_producer_retirement_executable_witness as
gate #64. Authoritative §1.8 row is #66; #64 is
substrate_gap_reflection_closure_closed (separate predicate).

Aligns brief with r3-program-plan.md §1.8 row identity per
INVARIANTS.md P1 (single authoritative facts).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): row #66 DECLARED → CONSUMER_LANDED per §1.7 taxonomy

Per codex/codex-default review on PR #2631 (REQUEST_CHANGES, review
9150): leaving row #66 at DECLARED while the Notes cell describes an
executable consumer that runs through TestRunner contradicts the §1.7
status taxonomy and INVARIANTS P2 single-authority discipline.

Promoting #66 to CONSUMER_LANDED with explicit PASSING gate on
residual = 0 (cascades from T-LensProducer-Retirement gates
#5 + #6 + #7). The F3 deferral is on PASSING, not CONSUMER_LANDED;
the executable receipt
src/v3/compiler/tests/integration/r3_lens_producer_retirement_executable_witness_test.rs
already exists and runs the .dag PB census claim through TestRunner.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 10, 2026
…2657)

acceptance per r3-structure.md:184

Reverts row #66 lens_producer_retirement_executable_witness in
docs/r3-program-plan.md from CONSUMER_LANDED back to DECLARED with
explicit canonical-acceptance framing.

Per briansrls + codex/codex-default BLOCKING reviews on merged PR #2631
(post-merge inline + main review at 2026-05-10T20:15Z): the
lens_producer_files_remaining census check shipped via PR #2595 is
the r3-structure.md:184 "near-term demo = retirement state-check +
doc receipts" placeholder, NOT the canonical demonstration consumer.

The canonical Pass-condition is "lens_apply reflection routes via
PB-Runtime on representative lens program" with execution-ready
witness DEFERRED to Row-4 equivalence receipt + Item 4 landing per
docs/design-pb-runtime-interpreter.md §5.1.

Promoting row #66 to CONSUMER_LANDED on the basis of substrate
plumbing dilutes the demonstration gate against INVARIANTS.md P2
single-authority discipline. Status re-promotes only when Row-4 +
Item 4 receipts land.

Also removes #66 from the post-T-LP drift-sweep brief's promotion
set with explicit exclusion-by-canonical-acceptance-scope rationale.

Other promotions in PR #2631 (#6 PASSING, #33 / #34 CONSUMER_LANDED)
stand — those rows have canonical-fit consumers landed.

Refs: PR #2631 #issuecomment thread (briansrls inline reviews +
codex review at sha 18d279c); r3-structure.md:184; design-pb-runtime
-interpreter.md §5.1.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 14, 2026
briansrls added a commit that referenced this pull request May 14, 2026
briansrls added a commit that referenced this pull request May 14, 2026
briansrls added a commit that referenced this pull request May 15, 2026
* retire pipeline include_str side channel ratchet

* WIP: R3 gate #34: bridge_include_str_side_channels_retired (T-Bridge-Retireme

* clean up pipeline include_str scanner

* document pipeline include_str sentinels

* Harden include_str pipeline ratchet scanner

* Handle lifetimes in pipeline include ratchet

* WIP: R3 gate #34: bridge_include_str_side_channels_retired (T-Bridge-Retireme

* WIP: R3 gate #34: bridge_include_str_side_channels_retired (T-Bridge-Retireme

* Handle raw string fragments in pipeline include ratchet

* Handle char fragments in pipeline include ratchet

* Decode escapes in pipeline include ratchet
briansrls added a commit that referenced this pull request May 22, 2026
* WIP: Variant-parameterization sweep resume — apply refined L1.4.b bar (PR #34

* WIP: Variant-parameterization sweep resume — apply refined L1.4.b bar (PR #34

* Refresh v4 float deprose header
@briansrls
briansrls deleted the claude/urgent-todos-XthMR branch June 1, 2026 18:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants