Skip to content

Auth pattern slice8 - #38

Closed
briansrls wants to merge 3 commits into
mainfrom
auth-pattern-slice8
Closed

briansrls wants to merge 3 commits into
mainfrom
auth-pattern-slice8

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

No description provided.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7408ac6467

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +197 to +203
match resolve_graph_cloud_config() {
Ok(config) => config,
Err(err) => {
if env_truthy(ENV_CONFIG_REQUIRED) {
panic!("cloud config resolution failed: {err}");
}
default_local_dev_config()

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Stop falling back on malformed cloud config

graph_cloud_config() currently falls back to default_local_dev_config() for any resolve_graph_cloud_config() error, not just the “no source configured” case documented above this function. If GUNBC_CLOUD_CONFIG_JSON/GUNBC_CLOUD_CONFIG_TOML is present but malformed (or references an unknown namespace), the process silently uses dev defaults instead of surfacing misconfiguration, which can route credential reads/writes to the wrong project/prefix in CI or production-like runs.

Useful? React with 👍 / 👎.

Comment on lines +194 to +197
scope_merge: if child.scope_merge == ScopeMergeMode::Replace {
self.scope_merge
} else {
child.scope_merge

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Honor child scope_merge override when merging defaults

The merge logic ignores a child profile’s scope_merge = replace by inheriting the parent mode whenever the child value is Replace. With a parent set to Union, a child cannot switch back to Replace, so inherited intent scopes keep unioning even when the child explicitly requests replacement. This makes profile inheritance behavior incorrect for valid policy configurations.

Useful? React with 👍 / 👎.

@briansrls briansrls closed this Feb 12, 2026
briansrls added a commit that referenced this pull request May 7, 2026
Director ratified α (narrow) at gunbc#828 c#4400772335 (relay via
Substrate Mgr at gunbc#2068 c#4401002201). β rejected per
feedback_isomorphism_or_generation_for_mirrors; γ-extended deferred to
its own Q-Lens-Target-Context PROPOSAL canvas.

Same-slice closure receipts:
  - Gate #38 (coercion_cost_equals_complexity_by_construction):
    SATISFIED-BY-CONSTRUCTION at HEAD — Semiring<SymbolicCost> sole
    composition authority at src/v3/std/algebra.dag:181-188
  - Gate #39 (no_coercion_cost_dimension):
    SATISFIED-BY-CONSTRUCTION at HEAD — SymbolicCost 7-variant sole
    cost dimension; no parallel CoercionCost carrier per grep

Deferred gates (#37 / #40 / #70) cite follow-on cross-cutting
Behavior→primitive-identity wiring canvas at #2175.

Updates:
  - docs/r3-program-plan.md §10.3 row: α-narrow disposition + #2175 link
  - docs/r3-program-plan.md gate table rows #37-#40 + #70: status update
  - docs/v3-lens-capability-register.md cost.dag row: α-narrow receipt
  - src/v3/lenses/cost.dag header + deferred-discussion: replace
    5-option matrix with Director-ratified α disposition + 4 findings

Refs: #2141; closes-by-construction §1.8 #38 + #39; defers #37/#40/#70
to #2175.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 7, 2026
briansrls added a commit that referenced this pull request May 7, 2026
briansrls added a commit that referenced this pull request May 7, 2026
…e question)

Sibling canvas to q-lens-target-context-canvas.md. Director α-revised
supersession at gunbc#828 #issuecomment-4400920572 elevated ε path (Rust-side
cost-composition wiring; preserves cost.dag PROXY) from slice-tier to
canvas-tier.

Authored per Q-PAFS template:
- Factoring claim: cost = (target-agnostic-shape SymbolicCost algebra) ×
  (target-specific-values per-primitive realization-cost data loaded Rust-side)
- Test against feedback_abstraction_layering (Director-named anchor at
  gunbc#828 c#4400921658): pure objective concepts × language-agnostic
  LanguageSpec × emit-side composition. Compliance test for each layer.
- Pro factoring (ε structurally honest): SymbolicCost algebra is target-
  agnostic at HEAD; Rust-side composition is natural home; #38/#39 substrate-
  already-aligned per Slice 1 finding.
- Con factoring (ε is parallel-representation debt): N parallel Rust-side
  compositions if multiple lenses need target-context; lens-framework
  abstraction stops at substrate boundary; future lenses hit same dilemma.

Mgr provisional reading: factoring honest for COST specifically; NOT
generalizable. ε right framing IF cost is the singular need + factoring
holds. If N>1 target-context-needing lenses surface, β-extended (option
(i) from sibling canvas) becomes the right path.

Director ratification ask: 3-way choice
  (ε) Cost-specific Rust-side composition; preserves cost.dag PROXY
  (β-extended option (i)) Lens<C> refactor for LanguageSpec parameter
  (both sequenced) ε now for cost; β-extended later if N>1

Framework discipline anchors:
- feedback_abstraction_layering (Director-named for this canvas)
- feedback_parallel_representation_debt
- feedback_same_slice_dissolution_discipline

Canvas-pair complete; sibling canvas + this canvas address the deeper
cross-cutting axis: target-context belongs .dag-side (β-extended) or
emit-side (ε)? Director ratification across both informs T-CostLens
follow-on slice + downstream lens architecture.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 8, 2026
…nded + Q-Cost-Composition-Layering ε) (#2181)

* docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 Variant-aware projection carrier canvas (#1947)

Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — same-slice prerequisite + section anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledger discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)

Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-Mgr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)

Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec8692): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — delete superseded canvas + name dissolution trigger for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)

cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — name dissolution trigger for DeclarationRef alias debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #2 + #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — consolidate split per-variant maps into single keyed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof canvas — 4-residual coproduct-dissolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authority map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85 — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof worker brief — γ ratified (2-variant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): descent_execution_proof — narrow EvidenceUnknown payload via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof — section-anchor cite for §10.3 row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> composition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scope-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition worker brief — γ ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Delete superseded T-CostLens canvas (worker brief is single live authority)

* docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demo (#1952) complexity-contract compile-error worker brief

Pre-staged execution brief per Director endorsement of T-LAS demos via direct
worker brief path (no canvas — design-lock at docs/design-lens-application-
surface.md specifies fixture shape verbatim at line 292).

7 same-slice acceptance gates: fixture program (O(n²) body + Enforce O(log n)
budget) + TestClaim assertion + diagnostic structural validation + no
regression on T-LBP cementing + bootstrap regen + clippy + §1.8 #92
advancement.

Hard prerequisites STOP-and-PING: T-LAS Slice A landed (gates #88-#91) AND
T-LBP complexity-lens BEHAVIORALLY COMPLETE (gate #79). Worker does not
author against partial substrate.

Sibling demos #1953 (CRDT cost) + #1954 (memory-peak cost) share the same
hard-prerequisite + TestClaim shape pattern — could dispatch as 3 sequential
PRs or single multi-demo PR (worker's call at dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demos #1953 + #1954 — cost-basis sibling worker brief

Pre-staged sibling brief covering both cost-basis demos (CRDT cost basis +
memory-peak cost basis) per Director endorsement of T-LAS demos via direct
worker-brief path. Single brief for two demos because they share:
- Hard-prerequisite pattern (T-LAS Slice A + T-LBP cost-lens BEHAVIORALLY COMPLETE)
- TestClaim + Diagnostic structural validation shape
- apply_lens(cost, ...) Enforce mode

Sibling of #1952 brief (complexity-contract compile-error). Worker's call at
dispatch on multi-demo PR vs sequential PRs (Mgr ratification needed if going
multi-demo).

#1953 (CRDT) substrate per design §4.2 + cost-basis-declaration audit at
docs/audit/t-user-authored-cost-basis-discipline-worked-examples.md.
#1954 (memory-peak) substrate per design §4.3; STOP-and-PING if
Dimension<SymbolicCost> substrate (deferred to Dimensions sub-lane per Director
ratification at gunbc#828 #issuecomment-4395691775) not yet landed.

6 same-slice acceptance gates per demo + same STOP-and-PING discipline as #1952.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens — update Sub-issue from #1957 to #2141 (post-surgical-recreate)

PM executed Director's surgical-recreate ratification (gunbc#828
#issuecomment-4397693699) at 17:54:43Z: closed #1957, created fresh #2141 to
trigger pollAutoSpawn fresh-creation path. Worker fierce-ram-21 (#2153) spawned
on #2141.

1-line brief update per Director's queued-action commitment: brief now
references #2141 + cites surgical-recreate authority. #1957 closed-as-superseded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context canvas (β-extended substrate-shape question)

Director α-revised supersession at gunbc#828 #issuecomment-4400920572 elevated
β-extended path (introduce first-precedent .dag-side fold-over-realization-rows
+ name active-target authority shape) from slice-tier to canvas-tier.

Authored per Q-PAFS template:
- Substrate-state at HEAD grep-verified (Lens<C>.read no target-context;
  zero .dag-side fold-over-realizations precedent; 15+ lens instances using
  generic Lens<C>)
- Binary question: should .dag-side lenses receive target-context for
  target-keyed reading?
- Options matrix: (i) LanguageSpec param to fold; (ii) per-target lens
  instances [parallel-representation debt]; (iii) global accessor [REJECTED
  global-state anti-pattern]
- Mgr provisional preference: (i)
- Cross-cutting: cost.dag load-bearing; emission_provenance.dag secondary;
  other 13+ lenses target-agnostic

Framework discipline anchors per Director corrections:
- feedback_same_slice_dissolution_discipline
- feedback_parallel_representation_debt
- feedback_abstraction_layering (sibling canvas)

Sibling canvas (ε path): q-cost-composition-layering-canvas.md authoring
follows. Both canvases together address deeper cross-cutting axis: does
target-context belong .dag-side (β-extended) or emit-side (ε)?

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Cost-Composition-Layering canvas (ε substrate-shape question)

Sibling canvas to q-lens-target-context-canvas.md. Director α-revised
supersession at gunbc#828 #issuecomment-4400920572 elevated ε path (Rust-side
cost-composition wiring; preserves cost.dag PROXY) from slice-tier to
canvas-tier.

Authored per Q-PAFS template:
- Factoring claim: cost = (target-agnostic-shape SymbolicCost algebra) ×
  (target-specific-values per-primitive realization-cost data loaded Rust-side)
- Test against feedback_abstraction_layering (Director-named anchor at
  gunbc#828 c#4400921658): pure objective concepts × language-agnostic
  LanguageSpec × emit-side composition. Compliance test for each layer.
- Pro factoring (ε structurally honest): SymbolicCost algebra is target-
  agnostic at HEAD; Rust-side composition is natural home; #38/#39 substrate-
  already-aligned per Slice 1 finding.
- Con factoring (ε is parallel-representation debt): N parallel Rust-side
  compositions if multiple lenses need target-context; lens-framework
  abstraction stops at substrate boundary; future lenses hit same dilemma.

Mgr provisional reading: factoring honest for COST specifically; NOT
generalizable. ε right framing IF cost is the singular need + factoring
holds. If N>1 target-context-needing lenses surface, β-extended (option
(i) from sibling canvas) becomes the right path.

Director ratification ask: 3-way choice
  (ε) Cost-specific Rust-side composition; preserves cost.dag PROXY
  (β-extended option (i)) Lens<C> refactor for LanguageSpec parameter
  (both sequenced) ε now for cost; β-extended later if N>1

Framework discipline anchors:
- feedback_abstraction_layering (Director-named for this canvas)
- feedback_parallel_representation_debt
- feedback_same_slice_dissolution_discipline

Canvas-pair complete; sibling canvas + this canvas address the deeper
cross-cutting axis: target-context belongs .dag-side (β-extended) or
emit-side (ε)? Director ratification across both informs T-CostLens
follow-on slice + downstream lens architecture.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: ε ratified canonical for cost; β-extended deferred to N=2 — gate updates

Director ratification at #2181 #issuecomment-... :
- (ε) RATIFIED standalone for cost composition (canonical-not-transitional)
- (β-extended option (i)) DEFERRED to N=2 trigger event (second lens with
  target-context need beyond cost)
- ("both sequenced") REJECTED as bridge-with-named-dissolution anti-pattern

Same-slice acceptance gates landed:

1. Q-Cost-Composition-Layering canvas: status updated from "ratification
   needed" → "Director-RATIFIED 2026-05-07 (ε standalone; canonical-not-
   transitional); PROPOSAL maturation pending"
2. Q-Lens-Target-Context canvas: status updated from "ratification needed"
   → "DRAFT/DEFERRED 2026-05-07; reopens on N=2 trigger event" (second lens
   with substantive target-context need; emission_provenance most likely
   candidate per cross-cutting analysis §3)
3. r3-program-plan.md gate-table rows #37 + #40 + #70: ε path ratified;
   close via Rust-side composition reading abstract SymbolicCost × per-
   primitive realization-cost in T-CostLens follow-on slice
4. r3-program-plan.md §10.3 T-CostLens-Composition row: ε ratified for
   #37/#40/#70; β-extended deferred per N=2 trigger
5. v3-lens-capability-register.md cost.dag row: ε disposition cited; #2175
   continues as cross-cutting umbrella tracker

Closed-system disposition per Director: if N=2 condition never fires,
β-extended never fires — structurally correct under closed-system design.

Framework discipline anchors honored:
- feedback_abstraction_layering: ε respects layering (objective concepts
  pure; target-specific values flow at emit time per Layer-3 honesty test)
- feedback_parallel_representation_debt: bounded to N=1; reopens at N=2
- feedback_same_slice_dissolution_discipline: ε ratified canonical, not
  transitional
- feedback_construction_over_ratchets: substrate-shape question answered
  structurally
- feedback_substrate_principle_audit: substrate-fact authored at canvas-
  tier; ratification follows P1 procedure

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvas inventory grounded in live src/v3/lenses/ registry

codex BLOCKING at #2181 (sha 00551a8): Q-Lens-Target-Context
canvas inventory was "copied from expected lens set instead of live
src/v3/lenses/ registry"; emission_provenance trigger references not
grounded in live file content.

Same shape of error as 3 prior BLOCKING reversals (Q-Reification, S5
DeclarationRef, T-CostLens merge-content). Substrate-state-grep is being
treated as retrospective-correction rather than prerequisite. Tightening:
this is the 4th occurrence; should be hard-prerequisite-discipline going
forward.

Fixes:

1. Q-Lens-Target-Context inventory section: replaced approximate "15+
   lens instances" framing with exact `ls`-grep registry (15 .dag files
   listed by name), notes infer_helpers + lower_helpers are helper
   modules authoring shared structural fns rather than top-level lens
   instances.

2. emission_provenance.dag analysis grounded in HEAD file status header:
   STATUS = STRUCTURALLY TERMINAL; LENS-INSTANCE FIXTURE-BOUND; BEHAVIORALLY
   DEFERRED. `read` body is fail-closed Empty stub. Lens does NOT currently
   read target-context inside fold; producer-side instrumentation records
   target-specific entries consumed via standard framework. Reframed as
   "ungrounded at HEAD" rather than "POSSIBLY target-context need" —
   re-evaluates at producer-wiring landing.

3. Net finding: N=1 confirmed at HEAD (cost.dag only); N=2 is empirically
   open pending lens-completion cycles, NOT pre-claimable.

Plus non-blocking improvement: Q-Cost-Composition-Layering line 9 stale
`#issuecomment-...` placeholder replaced with concrete ratification
comment id `#issuecomment-4401584012`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): fix Director-ratification-ask typo + #37 gate-id clarification footnote

cursor APPROVE_WITH_COMMENTS at #2181 (sha 4209eb7) flagged 2
NON-BLOCKING items + 1 exploratory:

1. (NON-BLOCKING) Q-Cost-Composition-Layering line 69: `## Directorratification ask` → `## Director ratification ask` (whitespace typo)
2. (NON-BLOCKING) Q-Cost-Composition-Layering line 9 placeholder `#issuecomment-...`: ALREADY ADDRESSED in commit `db88b1004` (replaced with `#issuecomment-4401584012`)
3. (Exploratory) Gate #37 id `cost_lens_reads_target_realization` framing implies .dag lens body performs realization read; per ε ratification it's Rust-side composition consumer. Added clarifying footnote noting gate-id retention + Rust-side closure path; rename candidate post-follow-on-slice landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — absorb PM canvas-review concerns 1-3

Director relayed PM canvas review at #2068 c#4401627536:

Concern 1 (RESOLVED via grep-verify): empirical N=1 confirmation. PM ran
`grep -lc 'TypeRealization|CallableRealization|MethodTemplateContract|
target_realization|realization_cost|LanguageSpec' src/v3/lenses/*.dag`;
only cost.dag has 3 hits, all 14 others have 0 refs (including
emission_provenance.dag which I'd previously framed speculatively).

Net-finding §3 updated with grep result inline + "N=1 empirically grounded"
framing replacing speculative "secondary candidate" language. Empirical
basis for DEFERRED β-extended disposition strengthened.

Concern 2 (Option (ii) multiplier framing): per-target lens instances
replicate the entire Lens<C> authoring surface — N×M × 4 (carrier + monoid
sequential + branch + iterate) authoring overhead. Updated Con bullet to
reflect the multiplier explicitly: 3 targets × 1 cost lens × 4 = 12 authored
fns; grows to 36 if 3 lenses need target-context. Cites
feedback_parallel_representation_debt as the P2 framing.

Concern 3 (Option (i) threading cost quantification): replaced narrative
"threading cost is real but manageable" with quantified breakdown — ~15
signature changes + 14 ignore-parameter patterns + 1 consumer + cementing-
test revalidation. Helps future Director ratification at N=2 trigger event.

All 3 amendments are docs-only refinements; ε ratification at gunbc#2181
c#4401584012 unchanged. Strengthens canvas as durable substrate-shape
decision record.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvases — collapse stale ratification-ask sections post-ratification

codex BLOCKING at #2181 (sha be9a9c9): both canvases had stale
"Director ratification ask" sections after status headers were updated to
RATIFIED/DEFERRED. Per INVARIANTS P1 "Documentation Describes Live State" —
canvas internally presented both settled and unsettled authority.

Fixes:

1. Q-Cost-Composition-Layering line 69-76: "Director ratification ask"
   section collapsed to "Director ratification (RECEIVED 2026-05-07)" with
   ε ratified, β-extended deferred, "both sequenced" rejected. Three options
   recorded as historical with ratification cite. Eliminates the rejected
   "both, sequenced" line that conflicted with status-header "canonical-not-
   transitional" framing.

2. Q-Lens-Target-Context line 131-136: "Director ratification ask" section
   collapsed to "Director disposition (DEFERRED 2026-05-07; reopens on N=2
   trigger event)". Original ratification asks recorded as FROZEN; revisit
   at N=2 trigger event with then-current substrate-state grep. Eliminates
   live-now-ratify framing that conflicted with status-header DEFERRED.

Both canvases now single live authority — RATIFIED/DEFERRED dispositions,
no internal ratification-ask drift. Future re-ratification (Q-Lens-Target-
Context at N=2 trigger) refreshes options matrix at that point per
substrate-state-honesty discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — separate live N=1 from reopen-only future N=2

openai-pro APPROVE_WITH_COMMENTS at #2181 (sha be9a9c9): canvas
line 127 mixed live N=1 authority with speculative N=2 candidate in one
current-state cost count.

Per P1 Documentation Describes Live State + P2 single-authority metadata:
the live count at HEAD is `cost × 3 targets = 3 per-target instances` (× 4
authoring-multiplier per Option (ii) Con = 12 fns). The `emission_provenance
× 3` figure is a reopen-only future scenario that materializes only if
emission_provenance becomes the second real target-context lens at producer-
wiring landing time.

Updated to separate the two clearly: live count + reopen-only future
scenario marked separately. Aligns with the grep-verified N=1 finding
established earlier in canvas §3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 8, 2026
…ined as context) (#2193)

* docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 Variant-aware projection carrier canvas (#1947)

Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — same-slice prerequisite + section anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledger discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)

Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-Mgr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)

Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec8692): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — delete superseded canvas + name dissolution trigger for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)

cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — name dissolution trigger for DeclarationRef alias debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #2 + #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — consolidate split per-variant maps into single keyed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof canvas — 4-residual coproduct-dissolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authority map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85 — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof worker brief — γ ratified (2-variant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): descent_execution_proof — narrow EvidenceUnknown payload via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof — section-anchor cite for §10.3 row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> composition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scope-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition worker brief — γ ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Delete superseded T-CostLens canvas (worker brief is single live authority)

* docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demo (#1952) complexity-contract compile-error worker brief

Pre-staged execution brief per Director endorsement of T-LAS demos via direct
worker brief path (no canvas — design-lock at docs/design-lens-application-
surface.md specifies fixture shape verbatim at line 292).

7 same-slice acceptance gates: fixture program (O(n²) body + Enforce O(log n)
budget) + TestClaim assertion + diagnostic structural validation + no
regression on T-LBP cementing + bootstrap regen + clippy + §1.8 #92
advancement.

Hard prerequisites STOP-and-PING: T-LAS Slice A landed (gates #88-#91) AND
T-LBP complexity-lens BEHAVIORALLY COMPLETE (gate #79). Worker does not
author against partial substrate.

Sibling demos #1953 (CRDT cost) + #1954 (memory-peak cost) share the same
hard-prerequisite + TestClaim shape pattern — could dispatch as 3 sequential
PRs or single multi-demo PR (worker's call at dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demos #1953 + #1954 — cost-basis sibling worker brief

Pre-staged sibling brief covering both cost-basis demos (CRDT cost basis +
memory-peak cost basis) per Director endorsement of T-LAS demos via direct
worker-brief path. Single brief for two demos because they share:
- Hard-prerequisite pattern (T-LAS Slice A + T-LBP cost-lens BEHAVIORALLY COMPLETE)
- TestClaim + Diagnostic structural validation shape
- apply_lens(cost, ...) Enforce mode

Sibling of #1952 brief (complexity-contract compile-error). Worker's call at
dispatch on multi-demo PR vs sequential PRs (Mgr ratification needed if going
multi-demo).

#1953 (CRDT) substrate per design §4.2 + cost-basis-declaration audit at
docs/audit/t-user-authored-cost-basis-discipline-worked-examples.md.
#1954 (memory-peak) substrate per design §4.3; STOP-and-PING if
Dimension<SymbolicCost> substrate (deferred to Dimensions sub-lane per Director
ratification at gunbc#828 #issuecomment-4395691775) not yet landed.

6 same-slice acceptance gates per demo + same STOP-and-PING discipline as #1952.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens — update Sub-issue from #1957 to #2141 (post-surgical-recreate)

PM executed Director's surgical-recreate ratification (gunbc#828
#issuecomment-4397693699) at 17:54:43Z: closed #1957, created fresh #2141 to
trigger pollAutoSpawn fresh-creation path. Worker fierce-ram-21 (#2153) spawned
on #2141.

1-line brief update per Director's queued-action commitment: brief now
references #2141 + cites surgical-recreate authority. #1957 closed-as-superseded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context canvas (β-extended substrate-shape question)

Director α-revised supersession at gunbc#828 #issuecomment-4400920572 elevated
β-extended path (introduce first-precedent .dag-side fold-over-realization-rows
+ name active-target authority shape) from slice-tier to canvas-tier.

Authored per Q-PAFS template:
- Substrate-state at HEAD grep-verified (Lens<C>.read no target-context;
  zero .dag-side fold-over-realizations precedent; 15+ lens instances using
  generic Lens<C>)
- Binary question: should .dag-side lenses receive target-context for
  target-keyed reading?
- Options matrix: (i) LanguageSpec param to fold; (ii) per-target lens
  instances [parallel-representation debt]; (iii) global accessor [REJECTED
  global-state anti-pattern]
- Mgr provisional preference: (i)
- Cross-cutting: cost.dag load-bearing; emission_provenance.dag secondary;
  other 13+ lenses target-agnostic

Framework discipline anchors per Director corrections:
- feedback_same_slice_dissolution_discipline
- feedback_parallel_representation_debt
- feedback_abstraction_layering (sibling canvas)

Sibling canvas (ε path): q-cost-composition-layering-canvas.md authoring
follows. Both canvases together address deeper cross-cutting axis: does
target-context belong .dag-side (β-extended) or emit-side (ε)?

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Cost-Composition-Layering canvas (ε substrate-shape question)

Sibling canvas to q-lens-target-context-canvas.md. Director α-revised
supersession at gunbc#828 #issuecomment-4400920572 elevated ε path (Rust-side
cost-composition wiring; preserves cost.dag PROXY) from slice-tier to
canvas-tier.

Authored per Q-PAFS template:
- Factoring claim: cost = (target-agnostic-shape SymbolicCost algebra) ×
  (target-specific-values per-primitive realization-cost data loaded Rust-side)
- Test against feedback_abstraction_layering (Director-named anchor at
  gunbc#828 c#4400921658): pure objective concepts × language-agnostic
  LanguageSpec × emit-side composition. Compliance test for each layer.
- Pro factoring (ε structurally honest): SymbolicCost algebra is target-
  agnostic at HEAD; Rust-side composition is natural home; #38/#39 substrate-
  already-aligned per Slice 1 finding.
- Con factoring (ε is parallel-representation debt): N parallel Rust-side
  compositions if multiple lenses need target-context; lens-framework
  abstraction stops at substrate boundary; future lenses hit same dilemma.

Mgr provisional reading: factoring honest for COST specifically; NOT
generalizable. ε right framing IF cost is the singular need + factoring
holds. If N>1 target-context-needing lenses surface, β-extended (option
(i) from sibling canvas) becomes the right path.

Director ratification ask: 3-way choice
  (ε) Cost-specific Rust-side composition; preserves cost.dag PROXY
  (β-extended option (i)) Lens<C> refactor for LanguageSpec parameter
  (both sequenced) ε now for cost; β-extended later if N>1

Framework discipline anchors:
- feedback_abstraction_layering (Director-named for this canvas)
- feedback_parallel_representation_debt
- feedback_same_slice_dissolution_discipline

Canvas-pair complete; sibling canvas + this canvas address the deeper
cross-cutting axis: target-context belongs .dag-side (β-extended) or
emit-side (ε)? Director ratification across both informs T-CostLens
follow-on slice + downstream lens architecture.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: ε ratified canonical for cost; β-extended deferred to N=2 — gate updates

Director ratification at #2181 #issuecomment-... :
- (ε) RATIFIED standalone for cost composition (canonical-not-transitional)
- (β-extended option (i)) DEFERRED to N=2 trigger event (second lens with
  target-context need beyond cost)
- ("both sequenced") REJECTED as bridge-with-named-dissolution anti-pattern

Same-slice acceptance gates landed:

1. Q-Cost-Composition-Layering canvas: status updated from "ratification
   needed" → "Director-RATIFIED 2026-05-07 (ε standalone; canonical-not-
   transitional); PROPOSAL maturation pending"
2. Q-Lens-Target-Context canvas: status updated from "ratification needed"
   → "DRAFT/DEFERRED 2026-05-07; reopens on N=2 trigger event" (second lens
   with substantive target-context need; emission_provenance most likely
   candidate per cross-cutting analysis §3)
3. r3-program-plan.md gate-table rows #37 + #40 + #70: ε path ratified;
   close via Rust-side composition reading abstract SymbolicCost × per-
   primitive realization-cost in T-CostLens follow-on slice
4. r3-program-plan.md §10.3 T-CostLens-Composition row: ε ratified for
   #37/#40/#70; β-extended deferred per N=2 trigger
5. v3-lens-capability-register.md cost.dag row: ε disposition cited; #2175
   continues as cross-cutting umbrella tracker

Closed-system disposition per Director: if N=2 condition never fires,
β-extended never fires — structurally correct under closed-system design.

Framework discipline anchors honored:
- feedback_abstraction_layering: ε respects layering (objective concepts
  pure; target-specific values flow at emit time per Layer-3 honesty test)
- feedback_parallel_representation_debt: bounded to N=1; reopens at N=2
- feedback_same_slice_dissolution_discipline: ε ratified canonical, not
  transitional
- feedback_construction_over_ratchets: substrate-shape question answered
  structurally
- feedback_substrate_principle_audit: substrate-fact authored at canvas-
  tier; ratification follows P1 procedure

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvas inventory grounded in live src/v3/lenses/ registry

codex BLOCKING at #2181 (sha 00551a8): Q-Lens-Target-Context
canvas inventory was "copied from expected lens set instead of live
src/v3/lenses/ registry"; emission_provenance trigger references not
grounded in live file content.

Same shape of error as 3 prior BLOCKING reversals (Q-Reification, S5
DeclarationRef, T-CostLens merge-content). Substrate-state-grep is being
treated as retrospective-correction rather than prerequisite. Tightening:
this is the 4th occurrence; should be hard-prerequisite-discipline going
forward.

Fixes:

1. Q-Lens-Target-Context inventory section: replaced approximate "15+
   lens instances" framing with exact `ls`-grep registry (15 .dag files
   listed by name), notes infer_helpers + lower_helpers are helper
   modules authoring shared structural fns rather than top-level lens
   instances.

2. emission_provenance.dag analysis grounded in HEAD file status header:
   STATUS = STRUCTURALLY TERMINAL; LENS-INSTANCE FIXTURE-BOUND; BEHAVIORALLY
   DEFERRED. `read` body is fail-closed Empty stub. Lens does NOT currently
   read target-context inside fold; producer-side instrumentation records
   target-specific entries consumed via standard framework. Reframed as
   "ungrounded at HEAD" rather than "POSSIBLY target-context need" —
   re-evaluates at producer-wiring landing.

3. Net finding: N=1 confirmed at HEAD (cost.dag only); N=2 is empirically
   open pending lens-completion cycles, NOT pre-claimable.

Plus non-blocking improvement: Q-Cost-Composition-Layering line 9 stale
`#issuecomment-...` placeholder replaced with concrete ratification
comment id `#issuecomment-4401584012`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): fix Director-ratification-ask typo + #37 gate-id clarification footnote

cursor APPROVE_WITH_COMMENTS at #2181 (sha 4209eb7) flagged 2
NON-BLOCKING items + 1 exploratory:

1. (NON-BLOCKING) Q-Cost-Composition-Layering line 69: `## Directorratification ask` → `## Director ratification ask` (whitespace typo)
2. (NON-BLOCKING) Q-Cost-Composition-Layering line 9 placeholder `#issuecomment-...`: ALREADY ADDRESSED in commit `db88b1004` (replaced with `#issuecomment-4401584012`)
3. (Exploratory) Gate #37 id `cost_lens_reads_target_realization` framing implies .dag lens body performs realization read; per ε ratification it's Rust-side composition consumer. Added clarifying footnote noting gate-id retention + Rust-side closure path; rename candidate post-follow-on-slice landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — absorb PM canvas-review concerns 1-3

Director relayed PM canvas review at #2068 c#4401627536:

Concern 1 (RESOLVED via grep-verify): empirical N=1 confirmation. PM ran
`grep -lc 'TypeRealization|CallableRealization|MethodTemplateContract|
target_realization|realization_cost|LanguageSpec' src/v3/lenses/*.dag`;
only cost.dag has 3 hits, all 14 others have 0 refs (including
emission_provenance.dag which I'd previously framed speculatively).

Net-finding §3 updated with grep result inline + "N=1 empirically grounded"
framing replacing speculative "secondary candidate" language. Empirical
basis for DEFERRED β-extended disposition strengthened.

Concern 2 (Option (ii) multiplier framing): per-target lens instances
replicate the entire Lens<C> authoring surface — N×M × 4 (carrier + monoid
sequential + branch + iterate) authoring overhead. Updated Con bullet to
reflect the multiplier explicitly: 3 targets × 1 cost lens × 4 = 12 authored
fns; grows to 36 if 3 lenses need target-context. Cites
feedback_parallel_representation_debt as the P2 framing.

Concern 3 (Option (i) threading cost quantification): replaced narrative
"threading cost is real but manageable" with quantified breakdown — ~15
signature changes + 14 ignore-parameter patterns + 1 consumer + cementing-
test revalidation. Helps future Director ratification at N=2 trigger event.

All 3 amendments are docs-only refinements; ε ratification at gunbc#2181
c#4401584012 unchanged. Strengthens canvas as durable substrate-shape
decision record.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvases — collapse stale ratification-ask sections post-ratification

codex BLOCKING at #2181 (sha be9a9c9): both canvases had stale
"Director ratification ask" sections after status headers were updated to
RATIFIED/DEFERRED. Per INVARIANTS P1 "Documentation Describes Live State" —
canvas internally presented both settled and unsettled authority.

Fixes:

1. Q-Cost-Composition-Layering line 69-76: "Director ratification ask"
   section collapsed to "Director ratification (RECEIVED 2026-05-07)" with
   ε ratified, β-extended deferred, "both sequenced" rejected. Three options
   recorded as historical with ratification cite. Eliminates the rejected
   "both, sequenced" line that conflicted with status-header "canonical-not-
   transitional" framing.

2. Q-Lens-Target-Context line 131-136: "Director ratification ask" section
   collapsed to "Director disposition (DEFERRED 2026-05-07; reopens on N=2
   trigger event)". Original ratification asks recorded as FROZEN; revisit
   at N=2 trigger event with then-current substrate-state grep. Eliminates
   live-now-ratify framing that conflicted with status-header DEFERRED.

Both canvases now single live authority — RATIFIED/DEFERRED dispositions,
no internal ratification-ask drift. Future re-ratification (Q-Lens-Target-
Context at N=2 trigger) refreshes options matrix at that point per
substrate-state-honesty discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — separate live N=1 from reopen-only future N=2

openai-pro APPROVE_WITH_COMMENTS at #2181 (sha be9a9c9): canvas
line 127 mixed live N=1 authority with speculative N=2 candidate in one
current-state cost count.

Per P1 Documentation Describes Live State + P2 single-authority metadata:
the live count at HEAD is `cost × 3 targets = 3 per-target instances` (× 4
authoring-multiplier per Option (ii) Con = 12 fns). The `emission_provenance
× 3` figure is a reopen-only future scenario that materializes only if
emission_provenance becomes the second real target-context lens at producer-
wiring landing time.

Updated to separate the two clearly: live count + reopen-only future
scenario marked separately. Aligns with the grep-verified N=1 finding
established earlier in canvas §3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): T-CostLens worker brief — ε supersession header (γ retained as context)

PR #2181 merged at eff426d ratifies ε path canonical-not-transitional
for cost composition. Brief was authored under γ scope (.dag-side
Lookup<SymbolicCost> composition). Add binding ε supersession header at
top; retain γ section as historical context per single-authority
discipline. cost.dag stays PROXY under ε; composition is Rust-side
(abstract SymbolicCost shape × per-primitive realization values).

Authority: Director ratification at #2181 #issuecomment-4401584012.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 8, 2026
…precedent does NOT apply) (#2197)

* docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 Variant-aware projection carrier canvas (#1947)

Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — same-slice prerequisite + section anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledger discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)

Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-Mgr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)

Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec8692): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — delete superseded canvas + name dissolution trigger for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)

cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — name dissolution trigger for DeclarationRef alias debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #2 + #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — consolidate split per-variant maps into single keyed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof canvas — 4-residual coproduct-dissolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authority map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85 — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof worker brief — γ ratified (2-variant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): descent_execution_proof — narrow EvidenceUnknown payload via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof — section-anchor cite for §10.3 row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> composition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scope-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition worker brief — γ ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Delete superseded T-CostLens canvas (worker brief is single live authority)

* docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demo (#1952) complexity-contract compile-error worker brief

Pre-staged execution brief per Director endorsement of T-LAS demos via direct
worker brief path (no canvas — design-lock at docs/design-lens-application-
surface.md specifies fixture shape verbatim at line 292).

7 same-slice acceptance gates: fixture program (O(n²) body + Enforce O(log n)
budget) + TestClaim assertion + diagnostic structural validation + no
regression on T-LBP cementing + bootstrap regen + clippy + §1.8 #92
advancement.

Hard prerequisites STOP-and-PING: T-LAS Slice A landed (gates #88-#91) AND
T-LBP complexity-lens BEHAVIORALLY COMPLETE (gate #79). Worker does not
author against partial substrate.

Sibling demos #1953 (CRDT cost) + #1954 (memory-peak cost) share the same
hard-prerequisite + TestClaim shape pattern — could dispatch as 3 sequential
PRs or single multi-demo PR (worker's call at dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demos #1953 + #1954 — cost-basis sibling worker brief

Pre-staged sibling brief covering both cost-basis demos (CRDT cost basis +
memory-peak cost basis) per Director endorsement of T-LAS demos via direct
worker-brief path. Single brief for two demos because they share:
- Hard-prerequisite pattern (T-LAS Slice A + T-LBP cost-lens BEHAVIORALLY COMPLETE)
- TestClaim + Diagnostic structural validation shape
- apply_lens(cost, ...) Enforce mode

Sibling of #1952 brief (complexity-contract compile-error). Worker's call at
dispatch on multi-demo PR vs sequential PRs (Mgr ratification needed if going
multi-demo).

#1953 (CRDT) substrate per design §4.2 + cost-basis-declaration audit at
docs/audit/t-user-authored-cost-basis-discipline-worked-examples.md.
#1954 (memory-peak) substrate per design §4.3; STOP-and-PING if
Dimension<SymbolicCost> substrate (deferred to Dimensions sub-lane per Director
ratification at gunbc#828 #issuecomment-4395691775) not yet landed.

6 same-slice acceptance gates per demo + same STOP-and-PING discipline as #1952.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens — update Sub-issue from #1957 to #2141 (post-surgical-recreate)

PM executed Director's surgical-recreate ratification (gunbc#828
#issuecomment-4397693699) at 17:54:43Z: closed #1957, created fresh #2141 to
trigger pollAutoSpawn fresh-creation path. Worker fierce-ram-21 (#2153) spawned
on #2141.

1-line brief update per Director's queued-action commitment: brief now
references #2141 + cites surgical-recreate authority. #1957 closed-as-superseded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context canvas (β-extended substrate-shape question)

Director α-revised supersession at gunbc#828 #issuecomment-4400920572 elevated
β-extended path (introduce first-precedent .dag-side fold-over-realization-rows
+ name active-target authority shape) from slice-tier to canvas-tier.

Authored per Q-PAFS template:
- Substrate-state at HEAD grep-verified (Lens<C>.read no target-context;
  zero .dag-side fold-over-realizations precedent; 15+ lens instances using
  generic Lens<C>)
- Binary question: should .dag-side lenses receive target-context for
  target-keyed reading?
- Options matrix: (i) LanguageSpec param to fold; (ii) per-target lens
  instances [parallel-representation debt]; (iii) global accessor [REJECTED
  global-state anti-pattern]
- Mgr provisional preference: (i)
- Cross-cutting: cost.dag load-bearing; emission_provenance.dag secondary;
  other 13+ lenses target-agnostic

Framework discipline anchors per Director corrections:
- feedback_same_slice_dissolution_discipline
- feedback_parallel_representation_debt
- feedback_abstraction_layering (sibling canvas)

Sibling canvas (ε path): q-cost-composition-layering-canvas.md authoring
follows. Both canvases together address deeper cross-cutting axis: does
target-context belong .dag-side (β-extended) or emit-side (ε)?

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Cost-Composition-Layering canvas (ε substrate-shape question)

Sibling canvas to q-lens-target-context-canvas.md. Director α-revised
supersession at gunbc#828 #issuecomment-4400920572 elevated ε path (Rust-side
cost-composition wiring; preserves cost.dag PROXY) from slice-tier to
canvas-tier.

Authored per Q-PAFS template:
- Factoring claim: cost = (target-agnostic-shape SymbolicCost algebra) ×
  (target-specific-values per-primitive realization-cost data loaded Rust-side)
- Test against feedback_abstraction_layering (Director-named anchor at
  gunbc#828 c#4400921658): pure objective concepts × language-agnostic
  LanguageSpec × emit-side composition. Compliance test for each layer.
- Pro factoring (ε structurally honest): SymbolicCost algebra is target-
  agnostic at HEAD; Rust-side composition is natural home; #38/#39 substrate-
  already-aligned per Slice 1 finding.
- Con factoring (ε is parallel-representation debt): N parallel Rust-side
  compositions if multiple lenses need target-context; lens-framework
  abstraction stops at substrate boundary; future lenses hit same dilemma.

Mgr provisional reading: factoring honest for COST specifically; NOT
generalizable. ε right framing IF cost is the singular need + factoring
holds. If N>1 target-context-needing lenses surface, β-extended (option
(i) from sibling canvas) becomes the right path.

Director ratification ask: 3-way choice
  (ε) Cost-specific Rust-side composition; preserves cost.dag PROXY
  (β-extended option (i)) Lens<C> refactor for LanguageSpec parameter
  (both sequenced) ε now for cost; β-extended later if N>1

Framework discipline anchors:
- feedback_abstraction_layering (Director-named for this canvas)
- feedback_parallel_representation_debt
- feedback_same_slice_dissolution_discipline

Canvas-pair complete; sibling canvas + this canvas address the deeper
cross-cutting axis: target-context belongs .dag-side (β-extended) or
emit-side (ε)? Director ratification across both informs T-CostLens
follow-on slice + downstream lens architecture.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: ε ratified canonical for cost; β-extended deferred to N=2 — gate updates

Director ratification at #2181 #issuecomment-... :
- (ε) RATIFIED standalone for cost composition (canonical-not-transitional)
- (β-extended option (i)) DEFERRED to N=2 trigger event (second lens with
  target-context need beyond cost)
- ("both sequenced") REJECTED as bridge-with-named-dissolution anti-pattern

Same-slice acceptance gates landed:

1. Q-Cost-Composition-Layering canvas: status updated from "ratification
   needed" → "Director-RATIFIED 2026-05-07 (ε standalone; canonical-not-
   transitional); PROPOSAL maturation pending"
2. Q-Lens-Target-Context canvas: status updated from "ratification needed"
   → "DRAFT/DEFERRED 2026-05-07; reopens on N=2 trigger event" (second lens
   with substantive target-context need; emission_provenance most likely
   candidate per cross-cutting analysis §3)
3. r3-program-plan.md gate-table rows #37 + #40 + #70: ε path ratified;
   close via Rust-side composition reading abstract SymbolicCost × per-
   primitive realization-cost in T-CostLens follow-on slice
4. r3-program-plan.md §10.3 T-CostLens-Composition row: ε ratified for
   #37/#40/#70; β-extended deferred per N=2 trigger
5. v3-lens-capability-register.md cost.dag row: ε disposition cited; #2175
   continues as cross-cutting umbrella tracker

Closed-system disposition per Director: if N=2 condition never fires,
β-extended never fires — structurally correct under closed-system design.

Framework discipline anchors honored:
- feedback_abstraction_layering: ε respects layering (objective concepts
  pure; target-specific values flow at emit time per Layer-3 honesty test)
- feedback_parallel_representation_debt: bounded to N=1; reopens at N=2
- feedback_same_slice_dissolution_discipline: ε ratified canonical, not
  transitional
- feedback_construction_over_ratchets: substrate-shape question answered
  structurally
- feedback_substrate_principle_audit: substrate-fact authored at canvas-
  tier; ratification follows P1 procedure

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvas inventory grounded in live src/v3/lenses/ registry

codex BLOCKING at #2181 (sha 00551a8): Q-Lens-Target-Context
canvas inventory was "copied from expected lens set instead of live
src/v3/lenses/ registry"; emission_provenance trigger references not
grounded in live file content.

Same shape of error as 3 prior BLOCKING reversals (Q-Reification, S5
DeclarationRef, T-CostLens merge-content). Substrate-state-grep is being
treated as retrospective-correction rather than prerequisite. Tightening:
this is the 4th occurrence; should be hard-prerequisite-discipline going
forward.

Fixes:

1. Q-Lens-Target-Context inventory section: replaced approximate "15+
   lens instances" framing with exact `ls`-grep registry (15 .dag files
   listed by name), notes infer_helpers + lower_helpers are helper
   modules authoring shared structural fns rather than top-level lens
   instances.

2. emission_provenance.dag analysis grounded in HEAD file status header:
   STATUS = STRUCTURALLY TERMINAL; LENS-INSTANCE FIXTURE-BOUND; BEHAVIORALLY
   DEFERRED. `read` body is fail-closed Empty stub. Lens does NOT currently
   read target-context inside fold; producer-side instrumentation records
   target-specific entries consumed via standard framework. Reframed as
   "ungrounded at HEAD" rather than "POSSIBLY target-context need" —
   re-evaluates at producer-wiring landing.

3. Net finding: N=1 confirmed at HEAD (cost.dag only); N=2 is empirically
   open pending lens-completion cycles, NOT pre-claimable.

Plus non-blocking improvement: Q-Cost-Composition-Layering line 9 stale
`#issuecomment-...` placeholder replaced with concrete ratification
comment id `#issuecomment-4401584012`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): fix Director-ratification-ask typo + #37 gate-id clarification footnote

cursor APPROVE_WITH_COMMENTS at #2181 (sha 4209eb7) flagged 2
NON-BLOCKING items + 1 exploratory:

1. (NON-BLOCKING) Q-Cost-Composition-Layering line 69: `## Directorratification ask` → `## Director ratification ask` (whitespace typo)
2. (NON-BLOCKING) Q-Cost-Composition-Layering line 9 placeholder `#issuecomment-...`: ALREADY ADDRESSED in commit `db88b1004` (replaced with `#issuecomment-4401584012`)
3. (Exploratory) Gate #37 id `cost_lens_reads_target_realization` framing implies .dag lens body performs realization read; per ε ratification it's Rust-side composition consumer. Added clarifying footnote noting gate-id retention + Rust-side closure path; rename candidate post-follow-on-slice landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — absorb PM canvas-review concerns 1-3

Director relayed PM canvas review at #2068 c#4401627536:

Concern 1 (RESOLVED via grep-verify): empirical N=1 confirmation. PM ran
`grep -lc 'TypeRealization|CallableRealization|MethodTemplateContract|
target_realization|realization_cost|LanguageSpec' src/v3/lenses/*.dag`;
only cost.dag has 3 hits, all 14 others have 0 refs (including
emission_provenance.dag which I'd previously framed speculatively).

Net-finding §3 updated with grep result inline + "N=1 empirically grounded"
framing replacing speculative "secondary candidate" language. Empirical
basis for DEFERRED β-extended disposition strengthened.

Concern 2 (Option (ii) multiplier framing): per-target lens instances
replicate the entire Lens<C> authoring surface — N×M × 4 (carrier + monoid
sequential + branch + iterate) authoring overhead. Updated Con bullet to
reflect the multiplier explicitly: 3 targets × 1 cost lens × 4 = 12 authored
fns; grows to 36 if 3 lenses need target-context. Cites
feedback_parallel_representation_debt as the P2 framing.

Concern 3 (Option (i) threading cost quantification): replaced narrative
"threading cost is real but manageable" with quantified breakdown — ~15
signature changes + 14 ignore-parameter patterns + 1 consumer + cementing-
test revalidation. Helps future Director ratification at N=2 trigger event.

All 3 amendments are docs-only refinements; ε ratification at gunbc#2181
c#4401584012 unchanged. Strengthens canvas as durable substrate-shape
decision record.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvases — collapse stale ratification-ask sections post-ratification

codex BLOCKING at #2181 (sha be9a9c9): both canvases had stale
"Director ratification ask" sections after status headers were updated to
RATIFIED/DEFERRED. Per INVARIANTS P1 "Documentation Describes Live State" —
canvas internally presented both settled and unsettled authority.

Fixes:

1. Q-Cost-Composition-Layering line 69-76: "Director ratification ask"
   section collapsed to "Director ratification (RECEIVED 2026-05-07)" with
   ε ratified, β-extended deferred, "both sequenced" rejected. Three options
   recorded as historical with ratification cite. Eliminates the rejected
   "both, sequenced" line that conflicted with status-header "canonical-not-
   transitional" framing.

2. Q-Lens-Target-Context line 131-136: "Director ratification ask" section
   collapsed to "Director disposition (DEFERRED 2026-05-07; reopens on N=2
   trigger event)". Original ratification asks recorded as FROZEN; revisit
   at N=2 trigger event with then-current substrate-state grep. Eliminates
   live-now-ratify framing that conflicted with status-header DEFERRED.

Both canvases now single live authority — RATIFIED/DEFERRED dispositions,
no internal ratification-ask drift. Future re-ratification (Q-Lens-Target-
Context at N=2 trigger) refreshes options matrix at that point per
substrate-state-honesty discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — separate live N=1 from reopen-only future N=2

openai-pro APPROVE_WITH_COMMENTS at #2181 (sha be9a9c9): canvas
line 127 mixed live N=1 authority with speculative N=2 candidate in one
current-state cost count.

Per P1 Documentation Describes Live State + P2 single-authority metadata:
the live count at HEAD is `cost × 3 targets = 3 per-target instances` (× 4
authoring-multiplier per Option (ii) Con = 12 fns). The `emission_provenance
× 3` figure is a reopen-only future scenario that materializes only if
emission_provenance becomes the second real target-context lens at producer-
wiring landing time.

Updated to separate the two clearly: live count + reopen-only future
scenario marked separately. Aligns with the grep-verified N=1 finding
established earlier in canvas §3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): T-CostLens worker brief — ε supersession header (γ retained as context)

PR #2181 merged at eff426d ratifies ε path canonical-not-transitional
for cost composition. Brief was authored under γ scope (.dag-side
Lookup<SymbolicCost> composition). Add binding ε supersession header at
top; retain γ section as historical context per single-authority
discipline. cost.dag stays PROXY under ε; composition is Rust-side
(abstract SymbolicCost shape × per-primitive realization values).

Authority: Director ratification at #2181 #issuecomment-4401584012.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Complexity-Composition-Layering canvas — DRAFT (factoring tested, ε precedent does NOT apply)

Director authorized canvas authoring at #828 c#4402669133 as
parallel structure to Q-Cost-Composition-Layering (ε RATIFIED). Substrate-
grep on src/v3/lenses/complexity.dag at HEAD shows the factoring claim
DIFFERS from cost-lens:

- Cost-lens needed (target-agnostic shape × target-specific values)
  factoring → Rust-side composition (ε)
- Complexity-lens has NO target-specific axis; output is structural
  property of DAG topology + algebra-instance composition; substrate-
  native fully-on-.dag-side completion

Mgr provisional reading: ε precedent does NOT apply; complexity-lens
BEHAVIORAL COMPLETION is direct slice-tier substrate authoring (carrier
introduction follows SymbolicCost precedent + T-E-P P1 carrier
consumption). Director ratification ask: Q1 (factoring finding correct),
Q2 (slice-tier directly bypassing canvas), Q3 (fresh worker pin).

Cross-Mgr: Verification Mgr (#2075) pinged on v2-oracle snapshot capture
status (cross-cutting prerequisite for #1950/#1951 cementing dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 8, 2026
* docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 Variant-aware projection carrier canvas (#1947)

Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — same-slice prerequisite + section anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledger discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)

Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-Mgr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)

Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec8692): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — delete superseded canvas + name dissolution trigger for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)

cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — name dissolution trigger for DeclarationRef alias debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #2 + #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — consolidate split per-variant maps into single keyed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof canvas — 4-residual coproduct-dissolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authority map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85 — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof worker brief — γ ratified (2-variant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): descent_execution_proof — narrow EvidenceUnknown payload via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof — section-anchor cite for §10.3 row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> composition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scope-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition worker brief — γ ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Delete superseded T-CostLens canvas (worker brief is single live authority)

* docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demo (#1952) complexity-contract compile-error worker brief

Pre-staged execution brief per Director endorsement of T-LAS demos via direct
worker brief path (no canvas — design-lock at docs/design-lens-application-
surface.md specifies fixture shape verbatim at line 292).

7 same-slice acceptance gates: fixture program (O(n²) body + Enforce O(log n)
budget) + TestClaim assertion + diagnostic structural validation + no
regression on T-LBP cementing + bootstrap regen + clippy + §1.8 #92
advancement.

Hard prerequisites STOP-and-PING: T-LAS Slice A landed (gates #88-#91) AND
T-LBP complexity-lens BEHAVIORALLY COMPLETE (gate #79). Worker does not
author against partial substrate.

Sibling demos #1953 (CRDT cost) + #1954 (memory-peak cost) share the same
hard-prerequisite + TestClaim shape pattern — could dispatch as 3 sequential
PRs or single multi-demo PR (worker's call at dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demos #1953 + #1954 — cost-basis sibling worker brief

Pre-staged sibling brief covering both cost-basis demos (CRDT cost basis +
memory-peak cost basis) per Director endorsement of T-LAS demos via direct
worker-brief path. Single brief for two demos because they share:
- Hard-prerequisite pattern (T-LAS Slice A + T-LBP cost-lens BEHAVIORALLY COMPLETE)
- TestClaim + Diagnostic structural validation shape
- apply_lens(cost, ...) Enforce mode

Sibling of #1952 brief (complexity-contract compile-error). Worker's call at
dispatch on multi-demo PR vs sequential PRs (Mgr ratification needed if going
multi-demo).

#1953 (CRDT) substrate per design §4.2 + cost-basis-declaration audit at
docs/audit/t-user-authored-cost-basis-discipline-worked-examples.md.
#1954 (memory-peak) substrate per design §4.3; STOP-and-PING if
Dimension<SymbolicCost> substrate (deferred to Dimensions sub-lane per Director
ratification at gunbc#828 #issuecomment-4395691775) not yet landed.

6 same-slice acceptance gates per demo + same STOP-and-PING discipline as #1952.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens — update Sub-issue from #1957 to #2141 (post-surgical-recreate)

PM executed Director's surgical-recreate ratification (gunbc#828
#issuecomment-4397693699) at 17:54:43Z: closed #1957, created fresh #2141 to
trigger pollAutoSpawn fresh-creation path. Worker fierce-ram-21 (#2153) spawned
on #2141.

1-line brief update per Director's queued-action commitment: brief now
references #2141 + cites surgical-recreate authority. #1957 closed-as-superseded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context canvas (β-extended substrate-shape question)

Director α-revised supersession at gunbc#828 #issuecomment-4400920572 elevated
β-extended path (introduce first-precedent .dag-side fold-over-realization-rows
+ name active-target authority shape) from slice-tier to canvas-tier.

Authored per Q-PAFS template:
- Substrate-state at HEAD grep-verified (Lens<C>.read no target-context;
  zero .dag-side fold-over-realizations precedent; 15+ lens instances using
  generic Lens<C>)
- Binary question: should .dag-side lenses receive target-context for
  target-keyed reading?
- Options matrix: (i) LanguageSpec param to fold; (ii) per-target lens
  instances [parallel-representation debt]; (iii) global accessor [REJECTED
  global-state anti-pattern]
- Mgr provisional preference: (i)
- Cross-cutting: cost.dag load-bearing; emission_provenance.dag secondary;
  other 13+ lenses target-agnostic

Framework discipline anchors per Director corrections:
- feedback_same_slice_dissolution_discipline
- feedback_parallel_representation_debt
- feedback_abstraction_layering (sibling canvas)

Sibling canvas (ε path): q-cost-composition-layering-canvas.md authoring
follows. Both canvases together address deeper cross-cutting axis: does
target-context belong .dag-side (β-extended) or emit-side (ε)?

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Cost-Composition-Layering canvas (ε substrate-shape question)

Sibling canvas to q-lens-target-context-canvas.md. Director α-revised
supersession at gunbc#828 #issuecomment-4400920572 elevated ε path (Rust-side
cost-composition wiring; preserves cost.dag PROXY) from slice-tier to
canvas-tier.

Authored per Q-PAFS template:
- Factoring claim: cost = (target-agnostic-shape SymbolicCost algebra) ×
  (target-specific-values per-primitive realization-cost data loaded Rust-side)
- Test against feedback_abstraction_layering (Director-named anchor at
  gunbc#828 c#4400921658): pure objective concepts × language-agnostic
  LanguageSpec × emit-side composition. Compliance test for each layer.
- Pro factoring (ε structurally honest): SymbolicCost algebra is target-
  agnostic at HEAD; Rust-side composition is natural home; #38/#39 substrate-
  already-aligned per Slice 1 finding.
- Con factoring (ε is parallel-representation debt): N parallel Rust-side
  compositions if multiple lenses need target-context; lens-framework
  abstraction stops at substrate boundary; future lenses hit same dilemma.

Mgr provisional reading: factoring honest for COST specifically; NOT
generalizable. ε right framing IF cost is the singular need + factoring
holds. If N>1 target-context-needing lenses surface, β-extended (option
(i) from sibling canvas) becomes the right path.

Director ratification ask: 3-way choice
  (ε) Cost-specific Rust-side composition; preserves cost.dag PROXY
  (β-extended option (i)) Lens<C> refactor for LanguageSpec parameter
  (both sequenced) ε now for cost; β-extended later if N>1

Framework discipline anchors:
- feedback_abstraction_layering (Director-named for this canvas)
- feedback_parallel_representation_debt
- feedback_same_slice_dissolution_discipline

Canvas-pair complete; sibling canvas + this canvas address the deeper
cross-cutting axis: target-context belongs .dag-side (β-extended) or
emit-side (ε)? Director ratification across both informs T-CostLens
follow-on slice + downstream lens architecture.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: ε ratified canonical for cost; β-extended deferred to N=2 — gate updates

Director ratification at #2181 #issuecomment-... :
- (ε) RATIFIED standalone for cost composition (canonical-not-transitional)
- (β-extended option (i)) DEFERRED to N=2 trigger event (second lens with
  target-context need beyond cost)
- ("both sequenced") REJECTED as bridge-with-named-dissolution anti-pattern

Same-slice acceptance gates landed:

1. Q-Cost-Composition-Layering canvas: status updated from "ratification
   needed" → "Director-RATIFIED 2026-05-07 (ε standalone; canonical-not-
   transitional); PROPOSAL maturation pending"
2. Q-Lens-Target-Context canvas: status updated from "ratification needed"
   → "DRAFT/DEFERRED 2026-05-07; reopens on N=2 trigger event" (second lens
   with substantive target-context need; emission_provenance most likely
   candidate per cross-cutting analysis §3)
3. r3-program-plan.md gate-table rows #37 + #40 + #70: ε path ratified;
   close via Rust-side composition reading abstract SymbolicCost × per-
   primitive realization-cost in T-CostLens follow-on slice
4. r3-program-plan.md §10.3 T-CostLens-Composition row: ε ratified for
   #37/#40/#70; β-extended deferred per N=2 trigger
5. v3-lens-capability-register.md cost.dag row: ε disposition cited; #2175
   continues as cross-cutting umbrella tracker

Closed-system disposition per Director: if N=2 condition never fires,
β-extended never fires — structurally correct under closed-system design.

Framework discipline anchors honored:
- feedback_abstraction_layering: ε respects layering (objective concepts
  pure; target-specific values flow at emit time per Layer-3 honesty test)
- feedback_parallel_representation_debt: bounded to N=1; reopens at N=2
- feedback_same_slice_dissolution_discipline: ε ratified canonical, not
  transitional
- feedback_construction_over_ratchets: substrate-shape question answered
  structurally
- feedback_substrate_principle_audit: substrate-fact authored at canvas-
  tier; ratification follows P1 procedure

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvas inventory grounded in live src/v3/lenses/ registry

codex BLOCKING at #2181 (sha 00551a8): Q-Lens-Target-Context
canvas inventory was "copied from expected lens set instead of live
src/v3/lenses/ registry"; emission_provenance trigger references not
grounded in live file content.

Same shape of error as 3 prior BLOCKING reversals (Q-Reification, S5
DeclarationRef, T-CostLens merge-content). Substrate-state-grep is being
treated as retrospective-correction rather than prerequisite. Tightening:
this is the 4th occurrence; should be hard-prerequisite-discipline going
forward.

Fixes:

1. Q-Lens-Target-Context inventory section: replaced approximate "15+
   lens instances" framing with exact `ls`-grep registry (15 .dag files
   listed by name), notes infer_helpers + lower_helpers are helper
   modules authoring shared structural fns rather than top-level lens
   instances.

2. emission_provenance.dag analysis grounded in HEAD file status header:
   STATUS = STRUCTURALLY TERMINAL; LENS-INSTANCE FIXTURE-BOUND; BEHAVIORALLY
   DEFERRED. `read` body is fail-closed Empty stub. Lens does NOT currently
   read target-context inside fold; producer-side instrumentation records
   target-specific entries consumed via standard framework. Reframed as
   "ungrounded at HEAD" rather than "POSSIBLY target-context need" —
   re-evaluates at producer-wiring landing.

3. Net finding: N=1 confirmed at HEAD (cost.dag only); N=2 is empirically
   open pending lens-completion cycles, NOT pre-claimable.

Plus non-blocking improvement: Q-Cost-Composition-Layering line 9 stale
`#issuecomment-...` placeholder replaced with concrete ratification
comment id `#issuecomment-4401584012`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): fix Director-ratification-ask typo + #37 gate-id clarification footnote

cursor APPROVE_WITH_COMMENTS at #2181 (sha 4209eb7) flagged 2
NON-BLOCKING items + 1 exploratory:

1. (NON-BLOCKING) Q-Cost-Composition-Layering line 69: `## Directorratification ask` → `## Director ratification ask` (whitespace typo)
2. (NON-BLOCKING) Q-Cost-Composition-Layering line 9 placeholder `#issuecomment-...`: ALREADY ADDRESSED in commit `db88b1004` (replaced with `#issuecomment-4401584012`)
3. (Exploratory) Gate #37 id `cost_lens_reads_target_realization` framing implies .dag lens body performs realization read; per ε ratification it's Rust-side composition consumer. Added clarifying footnote noting gate-id retention + Rust-side closure path; rename candidate post-follow-on-slice landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — absorb PM canvas-review concerns 1-3

Director relayed PM canvas review at #2068 c#4401627536:

Concern 1 (RESOLVED via grep-verify): empirical N=1 confirmation. PM ran
`grep -lc 'TypeRealization|CallableRealization|MethodTemplateContract|
target_realization|realization_cost|LanguageSpec' src/v3/lenses/*.dag`;
only cost.dag has 3 hits, all 14 others have 0 refs (including
emission_provenance.dag which I'd previously framed speculatively).

Net-finding §3 updated with grep result inline + "N=1 empirically grounded"
framing replacing speculative "secondary candidate" language. Empirical
basis for DEFERRED β-extended disposition strengthened.

Concern 2 (Option (ii) multiplier framing): per-target lens instances
replicate the entire Lens<C> authoring surface — N×M × 4 (carrier + monoid
sequential + branch + iterate) authoring overhead. Updated Con bullet to
reflect the multiplier explicitly: 3 targets × 1 cost lens × 4 = 12 authored
fns; grows to 36 if 3 lenses need target-context. Cites
feedback_parallel_representation_debt as the P2 framing.

Concern 3 (Option (i) threading cost quantification): replaced narrative
"threading cost is real but manageable" with quantified breakdown — ~15
signature changes + 14 ignore-parameter patterns + 1 consumer + cementing-
test revalidation. Helps future Director ratification at N=2 trigger event.

All 3 amendments are docs-only refinements; ε ratification at gunbc#2181
c#4401584012 unchanged. Strengthens canvas as durable substrate-shape
decision record.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvases — collapse stale ratification-ask sections post-ratification

codex BLOCKING at #2181 (sha be9a9c9): both canvases had stale
"Director ratification ask" sections after status headers were updated to
RATIFIED/DEFERRED. Per INVARIANTS P1 "Documentation Describes Live State" —
canvas internally presented both settled and unsettled authority.

Fixes:

1. Q-Cost-Composition-Layering line 69-76: "Director ratification ask"
   section collapsed to "Director ratification (RECEIVED 2026-05-07)" with
   ε ratified, β-extended deferred, "both sequenced" rejected. Three options
   recorded as historical with ratification cite. Eliminates the rejected
   "both, sequenced" line that conflicted with status-header "canonical-not-
   transitional" framing.

2. Q-Lens-Target-Context line 131-136: "Director ratification ask" section
   collapsed to "Director disposition (DEFERRED 2026-05-07; reopens on N=2
   trigger event)". Original ratification asks recorded as FROZEN; revisit
   at N=2 trigger event with then-current substrate-state grep. Eliminates
   live-now-ratify framing that conflicted with status-header DEFERRED.

Both canvases now single live authority — RATIFIED/DEFERRED dispositions,
no internal ratification-ask drift. Future re-ratification (Q-Lens-Target-
Context at N=2 trigger) refreshes options matrix at that point per
substrate-state-honesty discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — separate live N=1 from reopen-only future N=2

openai-pro APPROVE_WITH_COMMENTS at #2181 (sha be9a9c9): canvas
line 127 mixed live N=1 authority with speculative N=2 candidate in one
current-state cost count.

Per P1 Documentation Describes Live State + P2 single-authority metadata:
the live count at HEAD is `cost × 3 targets = 3 per-target instances` (× 4
authoring-multiplier per Option (ii) Con = 12 fns). The `emission_provenance
× 3` figure is a reopen-only future scenario that materializes only if
emission_provenance becomes the second real target-context lens at producer-
wiring landing time.

Updated to separate the two clearly: live count + reopen-only future
scenario marked separately. Aligns with the grep-verified N=1 finding
established earlier in canvas §3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): T-CostLens worker brief — ε supersession header (γ retained as context)

PR #2181 merged at eff426d ratifies ε path canonical-not-transitional
for cost composition. Brief was authored under γ scope (.dag-side
Lookup<SymbolicCost> composition). Add binding ε supersession header at
top; retain γ section as historical context per single-authority
discipline. cost.dag stays PROXY under ε; composition is Rust-side
(abstract SymbolicCost shape × per-primitive realization values).

Authority: Director ratification at #2181 #issuecomment-4401584012.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Complexity-Composition-Layering canvas — DRAFT (factoring tested, ε precedent does NOT apply)

Director authorized canvas authoring at #828 c#4402669133 as
parallel structure to Q-Cost-Composition-Layering (ε RATIFIED). Substrate-
grep on src/v3/lenses/complexity.dag at HEAD shows the factoring claim
DIFFERS from cost-lens:

- Cost-lens needed (target-agnostic shape × target-specific values)
  factoring → Rust-side composition (ε)
- Complexity-lens has NO target-specific axis; output is structural
  property of DAG topology + algebra-instance composition; substrate-
  native fully-on-.dag-side completion

Mgr provisional reading: ε precedent does NOT apply; complexity-lens
BEHAVIORAL COMPLETION is direct slice-tier substrate authoring (carrier
introduction follows SymbolicCost precedent + T-E-P P1 carrier
consumption). Director ratification ask: Q1 (factoring finding correct),
Q2 (slice-tier directly bypassing canvas), Q3 (fresh worker pin).

Cross-Mgr: Verification Mgr (#2075) pinged on v2-oracle snapshot capture
status (cross-cutting prerequisite for #1950/#1951 cementing dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LBP complexity-lens substrate-completion worker brief (Q1/Q2/Q3 RATIFIED)

Pre-authored brief for complexity-lens BEHAVIORAL COMPLETION substrate
work per Director Q1/Q2/Q3 ratification at #828 c#4402714255.

Three deliverables: carrier introduction (ComplexityCost / WorkSpan /
AsymptoticClass following SymbolicCost precedent) + lens widening
(complexity.dag PROXY → COMPLETE) + T-E-P P1 carrier consumption
(DescentEvidence / CallPattern / SubValueRelation for asymptotic
classification of recursive-call behavior).

Indirect-variant dependency surfaced as worker-grep concern at slice-
authoring time (T-E-P P1 Slice 5+ pending; eager-bat-178 stream).

Cementing test (#1950) is separate downstream brief; v2-oracle snapshot
ownership pending Q4 cross-Mgr ratification.

Worker pin: fresh-pool pick at dispatch time (NOT eager-bat-178 per
Director Q3 framing; NOT fierce-ram-21 busy with cost-lens ε).

Same-window-dispatch discipline applies post-canvas-merge (PR #2197).

Pre-authored vs pre-known discipline applied per
feedback_pre_known_vs_pre_authored_briefs.md memorialized 2026-05-08.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): rewrite complexity-lens brief consuming live design authority (codex BLOCKING fix)

Codex BLOCKING (3 findings) at #2199 sha 7a8bb6d:
1. Brief authored against missing canvas instead of reconciling with
   docs/design-complexity-lens-behavioral-completeness.md (which exists
   at HEAD with comprehensive substrate spec)
2. Producer coverage treated as optional corpus scope; should be hard
   T-E-P-Producer-Broadening prerequisite
3. Stale/non-in-repo planning authority cited; should be r3-structure.md
   row 146 (T-LBP slice 1)

All three BLOCKING findings VALID — substrate-grep-before-authoring
discipline failure on my part (feedback_substrate_grep_before_authoring
already memorialized; violated own discipline).

Rewrite delegates carrier shape, dimension wiring, and consumer rewrite
to live design doc §§1.1-1.6 verbatim:
- §1.1 SymbolicCost — already at algebra.dag; no change
- §1.2 SizeVariable — display_name enrichment
- §1.3 work_dimension + span_dimension — two AnalysisDimension instances
- §1.4 AsymptoticClass + BoundedLattice instance
- §1.5 Certainty (cost-aware composition; no lattice)
- §1.6 cost_bound_to_symbolic projection
- §1.7 ComplexitySummary record + lens widening

T-E-P P1 hard prerequisite per design's authority discipline + r3-
structure.md row 146; STOP-and-PING if T-E-P P1 not COMPLETE at slice
authoring time. Authority cites updated to live r3-structure.md row 146.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 8, 2026
…per Q6 RATIFIED) (#2209)

* docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 Variant-aware projection carrier canvas (#1947)

Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — same-slice prerequisite + section anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledger discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)

Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-Mgr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)

Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec8692): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — delete superseded canvas + name dissolution trigger for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)

cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — name dissolution trigger for DeclarationRef alias debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #2 + #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — consolidate split per-variant maps into single keyed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof canvas — 4-residual coproduct-dissolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authority map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85 — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof worker brief — γ ratified (2-variant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): descent_execution_proof — narrow EvidenceUnknown payload via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof — section-anchor cite for §10.3 row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> composition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scope-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition worker brief — γ ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Delete superseded T-CostLens canvas (worker brief is single live authority)

* docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demo (#1952) complexity-contract compile-error worker brief

Pre-staged execution brief per Director endorsement of T-LAS demos via direct
worker brief path (no canvas — design-lock at docs/design-lens-application-
surface.md specifies fixture shape verbatim at line 292).

7 same-slice acceptance gates: fixture program (O(n²) body + Enforce O(log n)
budget) + TestClaim assertion + diagnostic structural validation + no
regression on T-LBP cementing + bootstrap regen + clippy + §1.8 #92
advancement.

Hard prerequisites STOP-and-PING: T-LAS Slice A landed (gates #88-#91) AND
T-LBP complexity-lens BEHAVIORALLY COMPLETE (gate #79). Worker does not
author against partial substrate.

Sibling demos #1953 (CRDT cost) + #1954 (memory-peak cost) share the same
hard-prerequisite + TestClaim shape pattern — could dispatch as 3 sequential
PRs or single multi-demo PR (worker's call at dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demos #1953 + #1954 — cost-basis sibling worker brief

Pre-staged sibling brief covering both cost-basis demos (CRDT cost basis +
memory-peak cost basis) per Director endorsement of T-LAS demos via direct
worker-brief path. Single brief for two demos because they share:
- Hard-prerequisite pattern (T-LAS Slice A + T-LBP cost-lens BEHAVIORALLY COMPLETE)
- TestClaim + Diagnostic structural validation shape
- apply_lens(cost, ...) Enforce mode

Sibling of #1952 brief (complexity-contract compile-error). Worker's call at
dispatch on multi-demo PR vs sequential PRs (Mgr ratification needed if going
multi-demo).

#1953 (CRDT) substrate per design §4.2 + cost-basis-declaration audit at
docs/audit/t-user-authored-cost-basis-discipline-worked-examples.md.
#1954 (memory-peak) substrate per design §4.3; STOP-and-PING if
Dimension<SymbolicCost> substrate (deferred to Dimensions sub-lane per Director
ratification at gunbc#828 #issuecomment-4395691775) not yet landed.

6 same-slice acceptance gates per demo + same STOP-and-PING discipline as #1952.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens — update Sub-issue from #1957 to #2141 (post-surgical-recreate)

PM executed Director's surgical-recreate ratification (gunbc#828
#issuecomment-4397693699) at 17:54:43Z: closed #1957, created fresh #2141 to
trigger pollAutoSpawn fresh-creation path. Worker fierce-ram-21 (#2153) spawned
on #2141.

1-line brief update per Director's queued-action commitment: brief now
references #2141 + cites surgical-recreate authority. #1957 closed-as-superseded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context canvas (β-extended substrate-shape question)

Director α-revised supersession at gunbc#828 #issuecomment-4400920572 elevated
β-extended path (introduce first-precedent .dag-side fold-over-realization-rows
+ name active-target authority shape) from slice-tier to canvas-tier.

Authored per Q-PAFS template:
- Substrate-state at HEAD grep-verified (Lens<C>.read no target-context;
  zero .dag-side fold-over-realizations precedent; 15+ lens instances using
  generic Lens<C>)
- Binary question: should .dag-side lenses receive target-context for
  target-keyed reading?
- Options matrix: (i) LanguageSpec param to fold; (ii) per-target lens
  instances [parallel-representation debt]; (iii) global accessor [REJECTED
  global-state anti-pattern]
- Mgr provisional preference: (i)
- Cross-cutting: cost.dag load-bearing; emission_provenance.dag secondary;
  other 13+ lenses target-agnostic

Framework discipline anchors per Director corrections:
- feedback_same_slice_dissolution_discipline
- feedback_parallel_representation_debt
- feedback_abstraction_layering (sibling canvas)

Sibling canvas (ε path): q-cost-composition-layering-canvas.md authoring
follows. Both canvases together address deeper cross-cutting axis: does
target-context belong .dag-side (β-extended) or emit-side (ε)?

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Cost-Composition-Layering canvas (ε substrate-shape question)

Sibling canvas to q-lens-target-context-canvas.md. Director α-revised
supersession at gunbc#828 #issuecomment-4400920572 elevated ε path (Rust-side
cost-composition wiring; preserves cost.dag PROXY) from slice-tier to
canvas-tier.

Authored per Q-PAFS template:
- Factoring claim: cost = (target-agnostic-shape SymbolicCost algebra) ×
  (target-specific-values per-primitive realization-cost data loaded Rust-side)
- Test against feedback_abstraction_layering (Director-named anchor at
  gunbc#828 c#4400921658): pure objective concepts × language-agnostic
  LanguageSpec × emit-side composition. Compliance test for each layer.
- Pro factoring (ε structurally honest): SymbolicCost algebra is target-
  agnostic at HEAD; Rust-side composition is natural home; #38/#39 substrate-
  already-aligned per Slice 1 finding.
- Con factoring (ε is parallel-representation debt): N parallel Rust-side
  compositions if multiple lenses need target-context; lens-framework
  abstraction stops at substrate boundary; future lenses hit same dilemma.

Mgr provisional reading: factoring honest for COST specifically; NOT
generalizable. ε right framing IF cost is the singular need + factoring
holds. If N>1 target-context-needing lenses surface, β-extended (option
(i) from sibling canvas) becomes the right path.

Director ratification ask: 3-way choice
  (ε) Cost-specific Rust-side composition; preserves cost.dag PROXY
  (β-extended option (i)) Lens<C> refactor for LanguageSpec parameter
  (both sequenced) ε now for cost; β-extended later if N>1

Framework discipline anchors:
- feedback_abstraction_layering (Director-named for this canvas)
- feedback_parallel_representation_debt
- feedback_same_slice_dissolution_discipline

Canvas-pair complete; sibling canvas + this canvas address the deeper
cross-cutting axis: target-context belongs .dag-side (β-extended) or
emit-side (ε)? Director ratification across both informs T-CostLens
follow-on slice + downstream lens architecture.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: ε ratified canonical for cost; β-extended deferred to N=2 — gate updates

Director ratification at #2181 #issuecomment-... :
- (ε) RATIFIED standalone for cost composition (canonical-not-transitional)
- (β-extended option (i)) DEFERRED to N=2 trigger event (second lens with
  target-context need beyond cost)
- ("both sequenced") REJECTED as bridge-with-named-dissolution anti-pattern

Same-slice acceptance gates landed:

1. Q-Cost-Composition-Layering canvas: status updated from "ratification
   needed" → "Director-RATIFIED 2026-05-07 (ε standalone; canonical-not-
   transitional); PROPOSAL maturation pending"
2. Q-Lens-Target-Context canvas: status updated from "ratification needed"
   → "DRAFT/DEFERRED 2026-05-07; reopens on N=2 trigger event" (second lens
   with substantive target-context need; emission_provenance most likely
   candidate per cross-cutting analysis §3)
3. r3-program-plan.md gate-table rows #37 + #40 + #70: ε path ratified;
   close via Rust-side composition reading abstract SymbolicCost × per-
   primitive realization-cost in T-CostLens follow-on slice
4. r3-program-plan.md §10.3 T-CostLens-Composition row: ε ratified for
   #37/#40/#70; β-extended deferred per N=2 trigger
5. v3-lens-capability-register.md cost.dag row: ε disposition cited; #2175
   continues as cross-cutting umbrella tracker

Closed-system disposition per Director: if N=2 condition never fires,
β-extended never fires — structurally correct under closed-system design.

Framework discipline anchors honored:
- feedback_abstraction_layering: ε respects layering (objective concepts
  pure; target-specific values flow at emit time per Layer-3 honesty test)
- feedback_parallel_representation_debt: bounded to N=1; reopens at N=2
- feedback_same_slice_dissolution_discipline: ε ratified canonical, not
  transitional
- feedback_construction_over_ratchets: substrate-shape question answered
  structurally
- feedback_substrate_principle_audit: substrate-fact authored at canvas-
  tier; ratification follows P1 procedure

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvas inventory grounded in live src/v3/lenses/ registry

codex BLOCKING at #2181 (sha 00551a8): Q-Lens-Target-Context
canvas inventory was "copied from expected lens set instead of live
src/v3/lenses/ registry"; emission_provenance trigger references not
grounded in live file content.

Same shape of error as 3 prior BLOCKING reversals (Q-Reification, S5
DeclarationRef, T-CostLens merge-content). Substrate-state-grep is being
treated as retrospective-correction rather than prerequisite. Tightening:
this is the 4th occurrence; should be hard-prerequisite-discipline going
forward.

Fixes:

1. Q-Lens-Target-Context inventory section: replaced approximate "15+
   lens instances" framing with exact `ls`-grep registry (15 .dag files
   listed by name), notes infer_helpers + lower_helpers are helper
   modules authoring shared structural fns rather than top-level lens
   instances.

2. emission_provenance.dag analysis grounded in HEAD file status header:
   STATUS = STRUCTURALLY TERMINAL; LENS-INSTANCE FIXTURE-BOUND; BEHAVIORALLY
   DEFERRED. `read` body is fail-closed Empty stub. Lens does NOT currently
   read target-context inside fold; producer-side instrumentation records
   target-specific entries consumed via standard framework. Reframed as
   "ungrounded at HEAD" rather than "POSSIBLY target-context need" —
   re-evaluates at producer-wiring landing.

3. Net finding: N=1 confirmed at HEAD (cost.dag only); N=2 is empirically
   open pending lens-completion cycles, NOT pre-claimable.

Plus non-blocking improvement: Q-Cost-Composition-Layering line 9 stale
`#issuecomment-...` placeholder replaced with concrete ratification
comment id `#issuecomment-4401584012`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): fix Director-ratification-ask typo + #37 gate-id clarification footnote

cursor APPROVE_WITH_COMMENTS at #2181 (sha 4209eb7) flagged 2
NON-BLOCKING items + 1 exploratory:

1. (NON-BLOCKING) Q-Cost-Composition-Layering line 69: `## Directorratification ask` → `## Director ratification ask` (whitespace typo)
2. (NON-BLOCKING) Q-Cost-Composition-Layering line 9 placeholder `#issuecomment-...`: ALREADY ADDRESSED in commit `db88b1004` (replaced with `#issuecomment-4401584012`)
3. (Exploratory) Gate #37 id `cost_lens_reads_target_realization` framing implies .dag lens body performs realization read; per ε ratification it's Rust-side composition consumer. Added clarifying footnote noting gate-id retention + Rust-side closure path; rename candidate post-follow-on-slice landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — absorb PM canvas-review concerns 1-3

Director relayed PM canvas review at #2068 c#4401627536:

Concern 1 (RESOLVED via grep-verify): empirical N=1 confirmation. PM ran
`grep -lc 'TypeRealization|CallableRealization|MethodTemplateContract|
target_realization|realization_cost|LanguageSpec' src/v3/lenses/*.dag`;
only cost.dag has 3 hits, all 14 others have 0 refs (including
emission_provenance.dag which I'd previously framed speculatively).

Net-finding §3 updated with grep result inline + "N=1 empirically grounded"
framing replacing speculative "secondary candidate" language. Empirical
basis for DEFERRED β-extended disposition strengthened.

Concern 2 (Option (ii) multiplier framing): per-target lens instances
replicate the entire Lens<C> authoring surface — N×M × 4 (carrier + monoid
sequential + branch + iterate) authoring overhead. Updated Con bullet to
reflect the multiplier explicitly: 3 targets × 1 cost lens × 4 = 12 authored
fns; grows to 36 if 3 lenses need target-context. Cites
feedback_parallel_representation_debt as the P2 framing.

Concern 3 (Option (i) threading cost quantification): replaced narrative
"threading cost is real but manageable" with quantified breakdown — ~15
signature changes + 14 ignore-parameter patterns + 1 consumer + cementing-
test revalidation. Helps future Director ratification at N=2 trigger event.

All 3 amendments are docs-only refinements; ε ratification at gunbc#2181
c#4401584012 unchanged. Strengthens canvas as durable substrate-shape
decision record.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvases — collapse stale ratification-ask sections post-ratification

codex BLOCKING at #2181 (sha be9a9c9): both canvases had stale
"Director ratification ask" sections after status headers were updated to
RATIFIED/DEFERRED. Per INVARIANTS P1 "Documentation Describes Live State" —
canvas internally presented both settled and unsettled authority.

Fixes:

1. Q-Cost-Composition-Layering line 69-76: "Director ratification ask"
   section collapsed to "Director ratification (RECEIVED 2026-05-07)" with
   ε ratified, β-extended deferred, "both sequenced" rejected. Three options
   recorded as historical with ratification cite. Eliminates the rejected
   "both, sequenced" line that conflicted with status-header "canonical-not-
   transitional" framing.

2. Q-Lens-Target-Context line 131-136: "Director ratification ask" section
   collapsed to "Director disposition (DEFERRED 2026-05-07; reopens on N=2
   trigger event)". Original ratification asks recorded as FROZEN; revisit
   at N=2 trigger event with then-current substrate-state grep. Eliminates
   live-now-ratify framing that conflicted with status-header DEFERRED.

Both canvases now single live authority — RATIFIED/DEFERRED dispositions,
no internal ratification-ask drift. Future re-ratification (Q-Lens-Target-
Context at N=2 trigger) refreshes options matrix at that point per
substrate-state-honesty discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — separate live N=1 from reopen-only future N=2

openai-pro APPROVE_WITH_COMMENTS at #2181 (sha be9a9c9): canvas
line 127 mixed live N=1 authority with speculative N=2 candidate in one
current-state cost count.

Per P1 Documentation Describes Live State + P2 single-authority metadata:
the live count at HEAD is `cost × 3 targets = 3 per-target instances` (× 4
authoring-multiplier per Option (ii) Con = 12 fns). The `emission_provenance
× 3` figure is a reopen-only future scenario that materializes only if
emission_provenance becomes the second real target-context lens at producer-
wiring landing time.

Updated to separate the two clearly: live count + reopen-only future
scenario marked separately. Aligns with the grep-verified N=1 finding
established earlier in canvas §3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): T-CostLens worker brief — ε supersession header (γ retained as context)

PR #2181 merged at eff426d ratifies ε path canonical-not-transitional
for cost composition. Brief was authored under γ scope (.dag-side
Lookup<SymbolicCost> composition). Add binding ε supersession header at
top; retain γ section as historical context per single-authority
discipline. cost.dag stays PROXY under ε; composition is Rust-side
(abstract SymbolicCost shape × per-primitive realization values).

Authority: Director ratification at #2181 #issuecomment-4401584012.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Complexity-Composition-Layering canvas — DRAFT (factoring tested, ε precedent does NOT apply)

Director authorized canvas authoring at #828 c#4402669133 as
parallel structure to Q-Cost-Composition-Layering (ε RATIFIED). Substrate-
grep on src/v3/lenses/complexity.dag at HEAD shows the factoring claim
DIFFERS from cost-lens:

- Cost-lens needed (target-agnostic shape × target-specific values)
  factoring → Rust-side composition (ε)
- Complexity-lens has NO target-specific axis; output is structural
  property of DAG topology + algebra-instance composition; substrate-
  native fully-on-.dag-side completion

Mgr provisional reading: ε precedent does NOT apply; complexity-lens
BEHAVIORAL COMPLETION is direct slice-tier substrate authoring (carrier
introduction follows SymbolicCost precedent + T-E-P P1 carrier
consumption). Director ratification ask: Q1 (factoring finding correct),
Q2 (slice-tier directly bypassing canvas), Q3 (fresh worker pin).

Cross-Mgr: Verification Mgr (#2075) pinged on v2-oracle snapshot capture
status (cross-cutting prerequisite for #1950/#1951 cementing dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LBP complexity-lens substrate-completion worker brief (Q1/Q2/Q3 RATIFIED)

Pre-authored brief for complexity-lens BEHAVIORAL COMPLETION substrate
work per Director Q1/Q2/Q3 ratification at #828 c#4402714255.

Three deliverables: carrier introduction (ComplexityCost / WorkSpan /
AsymptoticClass following SymbolicCost precedent) + lens widening
(complexity.dag PROXY → COMPLETE) + T-E-P P1 carrier consumption
(DescentEvidence / CallPattern / SubValueRelation for asymptotic
classification of recursive-call behavior).

Indirect-variant dependency surfaced as worker-grep concern at slice-
authoring time (T-E-P P1 Slice 5+ pending; eager-bat-178 stream).

Cementing test (#1950) is separate downstream brief; v2-oracle snapshot
ownership pending Q4 cross-Mgr ratification.

Worker pin: fresh-pool pick at dispatch time (NOT eager-bat-178 per
Director Q3 framing; NOT fierce-ram-21 busy with cost-lens ε).

Same-window-dispatch discipline applies post-canvas-merge (PR #2197).

Pre-authored vs pre-known discipline applied per
feedback_pre_known_vs_pre_authored_briefs.md memorialized 2026-05-08.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): rewrite complexity-lens brief consuming live design authority (codex BLOCKING fix)

Codex BLOCKING (3 findings) at #2199 sha 7a8bb6d:
1. Brief authored against missing canvas instead of reconciling with
   docs/design-complexity-lens-behavioral-completeness.md (which exists
   at HEAD with comprehensive substrate spec)
2. Producer coverage treated as optional corpus scope; should be hard
   T-E-P-Producer-Broadening prerequisite
3. Stale/non-in-repo planning authority cited; should be r3-structure.md
   row 146 (T-LBP slice 1)

All three BLOCKING findings VALID — substrate-grep-before-authoring
discipline failure on my part (feedback_substrate_grep_before_authoring
already memorialized; violated own discipline).

Rewrite delegates carrier shape, dimension wiring, and consumer rewrite
to live design doc §§1.1-1.6 verbatim:
- §1.1 SymbolicCost — already at algebra.dag; no change
- §1.2 SizeVariable — display_name enrichment
- §1.3 work_dimension + span_dimension — two AnalysisDimension instances
- §1.4 AsymptoticClass + BoundedLattice instance
- §1.5 Certainty (cost-aware composition; no lattice)
- §1.6 cost_bound_to_symbolic projection
- §1.7 ComplexitySummary record + lens widening

T-E-P P1 hard prerequisite per design's authority discipline + r3-
structure.md row 146; STOP-and-PING if T-E-P P1 not COMPLETE at slice
authoring time. Authority cites updated to live r3-structure.md row 146.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas — DRAFT (canvas-tier P1 procedure per Q6 RATIFIED)

Director Q6 RATIFIED canvas-tier-required at #828 c#4403163639
for PerfWithinBaseline TestPredicate variant authoring. Three substantive
substrate-shape questions resolved:

Q1 baseline shape: (a) literal-Int rejected as strict-mirror-of-CostBounded
defeats semantic load; (b) DeclarationRef-to-stored-data composes
LensOutputEquals + data X: SymbolicCost precedent at HEAD; (c) runtime-
fixture-injection over-authors. Mgr lean (b).

Q2 ComparisonOp composition: (i) reuse existing ComparisonOp via test-
runner-side resolution matches LensOutputEquals path; (ii) new relative-
op-set introduces parallel-representation debt. Mgr lean (i).

Q3 baseline-storage scope: (α) in-scope slice authors example data; (β)
out-of-scope variant-only slice + PB consumer authors baseline data
matches existing layering. Mgr lean (β).

Combined Mgr lean: Q1(b) + Q2(i) + Q3(β) — variant authored as
compositional extension; baseline-storage is PB consumer-tier work.

Cross-Mgr: PB Mgr #2138 worker (crisp-swift-433) holds dispatch on #2204
land; T-Tier3-Dissolution #2085 R-4 prereq encoded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 8, 2026
…g-shape original) (#2210)

* docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 Variant-aware projection carrier canvas (#1947)

Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — same-slice prerequisite + section anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledger discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)

Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-Mgr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)

Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec8692): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — delete superseded canvas + name dissolution trigger for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)

cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — name dissolution trigger for DeclarationRef alias debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #2 + #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — consolidate split per-variant maps into single keyed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof canvas — 4-residual coproduct-dissolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authority map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85 — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof worker brief — γ ratified (2-variant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): descent_execution_proof — narrow EvidenceUnknown payload via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof — section-anchor cite for §10.3 row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> composition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scope-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition worker brief — γ ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Delete superseded T-CostLens canvas (worker brief is single live authority)

* docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demo (#1952) complexity-contract compile-error worker brief

Pre-staged execution brief per Director endorsement of T-LAS demos via direct
worker brief path (no canvas — design-lock at docs/design-lens-application-
surface.md specifies fixture shape verbatim at line 292).

7 same-slice acceptance gates: fixture program (O(n²) body + Enforce O(log n)
budget) + TestClaim assertion + diagnostic structural validation + no
regression on T-LBP cementing + bootstrap regen + clippy + §1.8 #92
advancement.

Hard prerequisites STOP-and-PING: T-LAS Slice A landed (gates #88-#91) AND
T-LBP complexity-lens BEHAVIORALLY COMPLETE (gate #79). Worker does not
author against partial substrate.

Sibling demos #1953 (CRDT cost) + #1954 (memory-peak cost) share the same
hard-prerequisite + TestClaim shape pattern — could dispatch as 3 sequential
PRs or single multi-demo PR (worker's call at dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demos #1953 + #1954 — cost-basis sibling worker brief

Pre-staged sibling brief covering both cost-basis demos (CRDT cost basis +
memory-peak cost basis) per Director endorsement of T-LAS demos via direct
worker-brief path. Single brief for two demos because they share:
- Hard-prerequisite pattern (T-LAS Slice A + T-LBP cost-lens BEHAVIORALLY COMPLETE)
- TestClaim + Diagnostic structural validation shape
- apply_lens(cost, ...) Enforce mode

Sibling of #1952 brief (complexity-contract compile-error). Worker's call at
dispatch on multi-demo PR vs sequential PRs (Mgr ratification needed if going
multi-demo).

#1953 (CRDT) substrate per design §4.2 + cost-basis-declaration audit at
docs/audit/t-user-authored-cost-basis-discipline-worked-examples.md.
#1954 (memory-peak) substrate per design §4.3; STOP-and-PING if
Dimension<SymbolicCost> substrate (deferred to Dimensions sub-lane per Director
ratification at gunbc#828 #issuecomment-4395691775) not yet landed.

6 same-slice acceptance gates per demo + same STOP-and-PING discipline as #1952.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens — update Sub-issue from #1957 to #2141 (post-surgical-recreate)

PM executed Director's surgical-recreate ratification (gunbc#828
#issuecomment-4397693699) at 17:54:43Z: closed #1957, created fresh #2141 to
trigger pollAutoSpawn fresh-creation path. Worker fierce-ram-21 (#2153) spawned
on #2141.

1-line brief update per Director's queued-action commitment: brief now
references #2141 + cites surgical-recreate authority. #1957 closed-as-superseded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context canvas (β-extended substrate-shape question)

Director α-revised supersession at gunbc#828 #issuecomment-4400920572 elevated
β-extended path (introduce first-precedent .dag-side fold-over-realization-rows
+ name active-target authority shape) from slice-tier to canvas-tier.

Authored per Q-PAFS template:
- Substrate-state at HEAD grep-verified (Lens<C>.read no target-context;
  zero .dag-side fold-over-realizations precedent; 15+ lens instances using
  generic Lens<C>)
- Binary question: should .dag-side lenses receive target-context for
  target-keyed reading?
- Options matrix: (i) LanguageSpec param to fold; (ii) per-target lens
  instances [parallel-representation debt]; (iii) global accessor [REJECTED
  global-state anti-pattern]
- Mgr provisional preference: (i)
- Cross-cutting: cost.dag load-bearing; emission_provenance.dag secondary;
  other 13+ lenses target-agnostic

Framework discipline anchors per Director corrections:
- feedback_same_slice_dissolution_discipline
- feedback_parallel_representation_debt
- feedback_abstraction_layering (sibling canvas)

Sibling canvas (ε path): q-cost-composition-layering-canvas.md authoring
follows. Both canvases together address deeper cross-cutting axis: does
target-context belong .dag-side (β-extended) or emit-side (ε)?

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Cost-Composition-Layering canvas (ε substrate-shape question)

Sibling canvas to q-lens-target-context-canvas.md. Director α-revised
supersession at gunbc#828 #issuecomment-4400920572 elevated ε path (Rust-side
cost-composition wiring; preserves cost.dag PROXY) from slice-tier to
canvas-tier.

Authored per Q-PAFS template:
- Factoring claim: cost = (target-agnostic-shape SymbolicCost algebra) ×
  (target-specific-values per-primitive realization-cost data loaded Rust-side)
- Test against feedback_abstraction_layering (Director-named anchor at
  gunbc#828 c#4400921658): pure objective concepts × language-agnostic
  LanguageSpec × emit-side composition. Compliance test for each layer.
- Pro factoring (ε structurally honest): SymbolicCost algebra is target-
  agnostic at HEAD; Rust-side composition is natural home; #38/#39 substrate-
  already-aligned per Slice 1 finding.
- Con factoring (ε is parallel-representation debt): N parallel Rust-side
  compositions if multiple lenses need target-context; lens-framework
  abstraction stops at substrate boundary; future lenses hit same dilemma.

Mgr provisional reading: factoring honest for COST specifically; NOT
generalizable. ε right framing IF cost is the singular need + factoring
holds. If N>1 target-context-needing lenses surface, β-extended (option
(i) from sibling canvas) becomes the right path.

Director ratification ask: 3-way choice
  (ε) Cost-specific Rust-side composition; preserves cost.dag PROXY
  (β-extended option (i)) Lens<C> refactor for LanguageSpec parameter
  (both sequenced) ε now for cost; β-extended later if N>1

Framework discipline anchors:
- feedback_abstraction_layering (Director-named for this canvas)
- feedback_parallel_representation_debt
- feedback_same_slice_dissolution_discipline

Canvas-pair complete; sibling canvas + this canvas address the deeper
cross-cutting axis: target-context belongs .dag-side (β-extended) or
emit-side (ε)? Director ratification across both informs T-CostLens
follow-on slice + downstream lens architecture.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: ε ratified canonical for cost; β-extended deferred to N=2 — gate updates

Director ratification at #2181 #issuecomment-... :
- (ε) RATIFIED standalone for cost composition (canonical-not-transitional)
- (β-extended option (i)) DEFERRED to N=2 trigger event (second lens with
  target-context need beyond cost)
- ("both sequenced") REJECTED as bridge-with-named-dissolution anti-pattern

Same-slice acceptance gates landed:

1. Q-Cost-Composition-Layering canvas: status updated from "ratification
   needed" → "Director-RATIFIED 2026-05-07 (ε standalone; canonical-not-
   transitional); PROPOSAL maturation pending"
2. Q-Lens-Target-Context canvas: status updated from "ratification needed"
   → "DRAFT/DEFERRED 2026-05-07; reopens on N=2 trigger event" (second lens
   with substantive target-context need; emission_provenance most likely
   candidate per cross-cutting analysis §3)
3. r3-program-plan.md gate-table rows #37 + #40 + #70: ε path ratified;
   close via Rust-side composition reading abstract SymbolicCost × per-
   primitive realization-cost in T-CostLens follow-on slice
4. r3-program-plan.md §10.3 T-CostLens-Composition row: ε ratified for
   #37/#40/#70; β-extended deferred per N=2 trigger
5. v3-lens-capability-register.md cost.dag row: ε disposition cited; #2175
   continues as cross-cutting umbrella tracker

Closed-system disposition per Director: if N=2 condition never fires,
β-extended never fires — structurally correct under closed-system design.

Framework discipline anchors honored:
- feedback_abstraction_layering: ε respects layering (objective concepts
  pure; target-specific values flow at emit time per Layer-3 honesty test)
- feedback_parallel_representation_debt: bounded to N=1; reopens at N=2
- feedback_same_slice_dissolution_discipline: ε ratified canonical, not
  transitional
- feedback_construction_over_ratchets: substrate-shape question answered
  structurally
- feedback_substrate_principle_audit: substrate-fact authored at canvas-
  tier; ratification follows P1 procedure

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvas inventory grounded in live src/v3/lenses/ registry

codex BLOCKING at #2181 (sha 00551a8): Q-Lens-Target-Context
canvas inventory was "copied from expected lens set instead of live
src/v3/lenses/ registry"; emission_provenance trigger references not
grounded in live file content.

Same shape of error as 3 prior BLOCKING reversals (Q-Reification, S5
DeclarationRef, T-CostLens merge-content). Substrate-state-grep is being
treated as retrospective-correction rather than prerequisite. Tightening:
this is the 4th occurrence; should be hard-prerequisite-discipline going
forward.

Fixes:

1. Q-Lens-Target-Context inventory section: replaced approximate "15+
   lens instances" framing with exact `ls`-grep registry (15 .dag files
   listed by name), notes infer_helpers + lower_helpers are helper
   modules authoring shared structural fns rather than top-level lens
   instances.

2. emission_provenance.dag analysis grounded in HEAD file status header:
   STATUS = STRUCTURALLY TERMINAL; LENS-INSTANCE FIXTURE-BOUND; BEHAVIORALLY
   DEFERRED. `read` body is fail-closed Empty stub. Lens does NOT currently
   read target-context inside fold; producer-side instrumentation records
   target-specific entries consumed via standard framework. Reframed as
   "ungrounded at HEAD" rather than "POSSIBLY target-context need" —
   re-evaluates at producer-wiring landing.

3. Net finding: N=1 confirmed at HEAD (cost.dag only); N=2 is empirically
   open pending lens-completion cycles, NOT pre-claimable.

Plus non-blocking improvement: Q-Cost-Composition-Layering line 9 stale
`#issuecomment-...` placeholder replaced with concrete ratification
comment id `#issuecomment-4401584012`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): fix Director-ratification-ask typo + #37 gate-id clarification footnote

cursor APPROVE_WITH_COMMENTS at #2181 (sha 4209eb7) flagged 2
NON-BLOCKING items + 1 exploratory:

1. (NON-BLOCKING) Q-Cost-Composition-Layering line 69: `## Directorratification ask` → `## Director ratification ask` (whitespace typo)
2. (NON-BLOCKING) Q-Cost-Composition-Layering line 9 placeholder `#issuecomment-...`: ALREADY ADDRESSED in commit `db88b1004` (replaced with `#issuecomment-4401584012`)
3. (Exploratory) Gate #37 id `cost_lens_reads_target_realization` framing implies .dag lens body performs realization read; per ε ratification it's Rust-side composition consumer. Added clarifying footnote noting gate-id retention + Rust-side closure path; rename candidate post-follow-on-slice landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — absorb PM canvas-review concerns 1-3

Director relayed PM canvas review at #2068 c#4401627536:

Concern 1 (RESOLVED via grep-verify): empirical N=1 confirmation. PM ran
`grep -lc 'TypeRealization|CallableRealization|MethodTemplateContract|
target_realization|realization_cost|LanguageSpec' src/v3/lenses/*.dag`;
only cost.dag has 3 hits, all 14 others have 0 refs (including
emission_provenance.dag which I'd previously framed speculatively).

Net-finding §3 updated with grep result inline + "N=1 empirically grounded"
framing replacing speculative "secondary candidate" language. Empirical
basis for DEFERRED β-extended disposition strengthened.

Concern 2 (Option (ii) multiplier framing): per-target lens instances
replicate the entire Lens<C> authoring surface — N×M × 4 (carrier + monoid
sequential + branch + iterate) authoring overhead. Updated Con bullet to
reflect the multiplier explicitly: 3 targets × 1 cost lens × 4 = 12 authored
fns; grows to 36 if 3 lenses need target-context. Cites
feedback_parallel_representation_debt as the P2 framing.

Concern 3 (Option (i) threading cost quantification): replaced narrative
"threading cost is real but manageable" with quantified breakdown — ~15
signature changes + 14 ignore-parameter patterns + 1 consumer + cementing-
test revalidation. Helps future Director ratification at N=2 trigger event.

All 3 amendments are docs-only refinements; ε ratification at gunbc#2181
c#4401584012 unchanged. Strengthens canvas as durable substrate-shape
decision record.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvases — collapse stale ratification-ask sections post-ratification

codex BLOCKING at #2181 (sha be9a9c9): both canvases had stale
"Director ratification ask" sections after status headers were updated to
RATIFIED/DEFERRED. Per INVARIANTS P1 "Documentation Describes Live State" —
canvas internally presented both settled and unsettled authority.

Fixes:

1. Q-Cost-Composition-Layering line 69-76: "Director ratification ask"
   section collapsed to "Director ratification (RECEIVED 2026-05-07)" with
   ε ratified, β-extended deferred, "both sequenced" rejected. Three options
   recorded as historical with ratification cite. Eliminates the rejected
   "both, sequenced" line that conflicted with status-header "canonical-not-
   transitional" framing.

2. Q-Lens-Target-Context line 131-136: "Director ratification ask" section
   collapsed to "Director disposition (DEFERRED 2026-05-07; reopens on N=2
   trigger event)". Original ratification asks recorded as FROZEN; revisit
   at N=2 trigger event with then-current substrate-state grep. Eliminates
   live-now-ratify framing that conflicted with status-header DEFERRED.

Both canvases now single live authority — RATIFIED/DEFERRED dispositions,
no internal ratification-ask drift. Future re-ratification (Q-Lens-Target-
Context at N=2 trigger) refreshes options matrix at that point per
substrate-state-honesty discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — separate live N=1 from reopen-only future N=2

openai-pro APPROVE_WITH_COMMENTS at #2181 (sha be9a9c9): canvas
line 127 mixed live N=1 authority with speculative N=2 candidate in one
current-state cost count.

Per P1 Documentation Describes Live State + P2 single-authority metadata:
the live count at HEAD is `cost × 3 targets = 3 per-target instances` (× 4
authoring-multiplier per Option (ii) Con = 12 fns). The `emission_provenance
× 3` figure is a reopen-only future scenario that materializes only if
emission_provenance becomes the second real target-context lens at producer-
wiring landing time.

Updated to separate the two clearly: live count + reopen-only future
scenario marked separately. Aligns with the grep-verified N=1 finding
established earlier in canvas §3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): T-CostLens worker brief — ε supersession header (γ retained as context)

PR #2181 merged at eff426d ratifies ε path canonical-not-transitional
for cost composition. Brief was authored under γ scope (.dag-side
Lookup<SymbolicCost> composition). Add binding ε supersession header at
top; retain γ section as historical context per single-authority
discipline. cost.dag stays PROXY under ε; composition is Rust-side
(abstract SymbolicCost shape × per-primitive realization values).

Authority: Director ratification at #2181 #issuecomment-4401584012.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Complexity-Composition-Layering canvas — DRAFT (factoring tested, ε precedent does NOT apply)

Director authorized canvas authoring at #828 c#4402669133 as
parallel structure to Q-Cost-Composition-Layering (ε RATIFIED). Substrate-
grep on src/v3/lenses/complexity.dag at HEAD shows the factoring claim
DIFFERS from cost-lens:

- Cost-lens needed (target-agnostic shape × target-specific values)
  factoring → Rust-side composition (ε)
- Complexity-lens has NO target-specific axis; output is structural
  property of DAG topology + algebra-instance composition; substrate-
  native fully-on-.dag-side completion

Mgr provisional reading: ε precedent does NOT apply; complexity-lens
BEHAVIORAL COMPLETION is direct slice-tier substrate authoring (carrier
introduction follows SymbolicCost precedent + T-E-P P1 carrier
consumption). Director ratification ask: Q1 (factoring finding correct),
Q2 (slice-tier directly bypassing canvas), Q3 (fresh worker pin).

Cross-Mgr: Verification Mgr (#2075) pinged on v2-oracle snapshot capture
status (cross-cutting prerequisite for #1950/#1951 cementing dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LBP complexity-lens substrate-completion worker brief (Q1/Q2/Q3 RATIFIED)

Pre-authored brief for complexity-lens BEHAVIORAL COMPLETION substrate
work per Director Q1/Q2/Q3 ratification at #828 c#4402714255.

Three deliverables: carrier introduction (ComplexityCost / WorkSpan /
AsymptoticClass following SymbolicCost precedent) + lens widening
(complexity.dag PROXY → COMPLETE) + T-E-P P1 carrier consumption
(DescentEvidence / CallPattern / SubValueRelation for asymptotic
classification of recursive-call behavior).

Indirect-variant dependency surfaced as worker-grep concern at slice-
authoring time (T-E-P P1 Slice 5+ pending; eager-bat-178 stream).

Cementing test (#1950) is separate downstream brief; v2-oracle snapshot
ownership pending Q4 cross-Mgr ratification.

Worker pin: fresh-pool pick at dispatch time (NOT eager-bat-178 per
Director Q3 framing; NOT fierce-ram-21 busy with cost-lens ε).

Same-window-dispatch discipline applies post-canvas-merge (PR #2197).

Pre-authored vs pre-known discipline applied per
feedback_pre_known_vs_pre_authored_briefs.md memorialized 2026-05-08.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): rewrite complexity-lens brief consuming live design authority (codex BLOCKING fix)

Codex BLOCKING (3 findings) at #2199 sha 7a8bb6d:
1. Brief authored against missing canvas instead of reconciling with
   docs/design-complexity-lens-behavioral-completeness.md (which exists
   at HEAD with comprehensive substrate spec)
2. Producer coverage treated as optional corpus scope; should be hard
   T-E-P-Producer-Broadening prerequisite
3. Stale/non-in-repo planning authority cited; should be r3-structure.md
   row 146 (T-LBP slice 1)

All three BLOCKING findings VALID — substrate-grep-before-authoring
discipline failure on my part (feedback_substrate_grep_before_authoring
already memorialized; violated own discipline).

Rewrite delegates carrier shape, dimension wiring, and consumer rewrite
to live design doc §§1.1-1.6 verbatim:
- §1.1 SymbolicCost — already at algebra.dag; no change
- §1.2 SizeVariable — display_name enrichment
- §1.3 work_dimension + span_dimension — two AnalysisDimension instances
- §1.4 AsymptoticClass + BoundedLattice instance
- §1.5 Certainty (cost-aware composition; no lattice)
- §1.6 cost_bound_to_symbolic projection
- §1.7 ComplexitySummary record + lens widening

T-E-P P1 hard prerequisite per design's authority discipline + r3-
structure.md row 146; STOP-and-PING if T-E-P P1 not COMPLETE at slice
authoring time. Authority cites updated to live r3-structure.md row 146.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas — DRAFT (canvas-tier P1 procedure per Q6 RATIFIED)

Director Q6 RATIFIED canvas-tier-required at #828 c#4403163639
for PerfWithinBaseline TestPredicate variant authoring. Three substantive
substrate-shape questions resolved:

Q1 baseline shape: (a) literal-Int rejected as strict-mirror-of-CostBounded
defeats semantic load; (b) DeclarationRef-to-stored-data composes
LensOutputEquals + data X: SymbolicCost precedent at HEAD; (c) runtime-
fixture-injection over-authors. Mgr lean (b).

Q2 ComparisonOp composition: (i) reuse existing ComparisonOp via test-
runner-side resolution matches LensOutputEquals path; (ii) new relative-
op-set introduces parallel-representation debt. Mgr lean (i).

Q3 baseline-storage scope: (α) in-scope slice authors example data; (β)
out-of-scope variant-only slice + PB consumer authors baseline data
matches existing layering. Mgr lean (β).

Combined Mgr lean: Q1(b) + Q2(i) + Q3(β) — variant authored as
compositional extension; baseline-storage is PB consumer-tier work.

Cross-Mgr: PB Mgr #2138 worker (crisp-swift-433) holds dispatch on #2204
land; T-Tier3-Dissolution #2085 R-4 prereq encoded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas REVISED (supersedes wrong-shape original)

Director disposition at #828 c#4403265220 authorized
supersession after BLOCKING at PR #2209 c#4403246233 verified VALID:
original canvas conflated symbolic SymbolicCost (cost-lens substrate)
with wall-clock measured median/p99 baseline (T-Tier3 perf gate
substrate per docs/r3-structure.md:225 + :461 Director-locked 2026-04-28).

Revised canvas frames as two-path ratification:
- P1 author full perf-budget substrate in-R3 (multi-slice; pattern-5
  genuinely-novel substrate-fact-introduction)
- P2 explicitly post-R3 per Director-locked recommendation (zero in-R3
  effort; structural close per r3-structure.md:461 'R3 deliverable is
  structural close; perf is downstream')

Mgr lean: P2 — Director-locked recommendation explicit; trigger-
condition ('someone authors perf-budget claim with concrete numbers
and tooling') not met; R3 horizon constraint argues against multi-
slice perf-budget substrate adding to 5-orthogonal-dependency picture.

Original canvas at q-perf-within-baseline-canvas.md retained with
SUPERSEDED-BY header per durable-decision-record discipline.

5th discipline-failure of 2026-05-08 cycle: substrate-grep verified
substrate-precedent but missed consumer-side requirement at canonical
authority doc; Director self-flagged symmetric two-axis verification
gap; canvas-finding-taxonomy needs precondition 'consumer-side
requirement grep-verified at canonical authority doc'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas-revised — correct trigger-condition framing per Director c#4403297623

Director caught second-axis grep failure on revised canvas: my P2
reasoning #1 ("path-trigger condition for P1 is not met") was
structurally wrong. Existing tooling at HEAD substantially meets the
Director-locked 2026-04-28 trigger-condition ("someone authors the
perf-budget claim with concrete numbers and tooling"):

- docs/briefs/r3-pb-tier3-perf-budget-worker.md
- docs/audit/c1-tier3-perf-budget-readiness-matrix.md
- src/v3/compiler/benches/tier3_mirror_perf.rs
- docs/audit/c1-tier3-baseline-capture-procedure.md
- docs/audit/c1-r3-canonical-bench-host-decision-matrix.md

Plus thresholds (≤2× median, ≤5× p99) + capture discipline (N=3 min,
N=5 preferred) + canonical bench host option matrix.

P1 is bridging existing tooling to substrate (compositional-extension),
NOT multi-slice greenfield genuinely-novel pattern-5 as originally
framed. Smaller scope than canvas-finding-taxonomy pattern 5 implies.

Path-call genuinely depends on PB Mgr's R-3 (canonical CI bench host)
+ R-7 (tier3_baseline.json baseline-capture path) decisions per their
audit response at c#4403059897. Path-call DEFERRED to cross-Mgr
coordination outcome with PB Mgr (#2074); Substrate Mgr surfaces with
corrected framing this turn.

Sixth discipline-failure of cycle (mine, second-axis grep gap on
existing-tooling state); same-class as Director's first-axis grep gap
on consumer-side requirement at the prior turn. Memorialized as
two-axis verification discipline anchor.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 8, 2026
… recreated [supersedes #1957] (#2194)

* WIP: Substrate T-CostLens-Composition behavioral completion (γ-ratified) — re

* WIP: Substrate T-CostLens-Composition behavioral completion (γ-ratified) — re

* docs(lenses): cost.dag deferred-discussion — α-revised Slice A0 receipts

Drops unused CallableRealization + DeclarationId imports per codex review
on PR #2171 (imports were scaffolding for the Slice A1 helper which is
HELD pending Director ratification).

Adds T-CostLens-Composition status block citing γ-ratification +
5-option matrix (α-revised / α / β / β-extended / ε / γ-extended) +
4 structural findings forcing the matrix:
  1. No `data cost_lens: Lens<SymbolicCost>` row at HEAD
  2. `Lens<C>.read` carries no target-context (STOP criterion #1)
  3. Behavior→primitive-identity tractable via TransformTarget
  4. No `.dag`-side `List<CallableRealization>` iteration precedent

Per Substrate Mgr disposition at gunbc#2068 #issuecomment-4400747562:
α-revised pure-docs landing while Director ratification at gunbc#828
#issuecomment-4400401643 stays open.

Refs: #2141

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: T-CostLens-Composition α-narrow receipts — gates #38 + #39 closure

Director ratified α (narrow) at gunbc#828 c#4400772335 (relay via
Substrate Mgr at gunbc#2068 c#4401002201). β rejected per
feedback_isomorphism_or_generation_for_mirrors; γ-extended deferred to
its own Q-Lens-Target-Context PROPOSAL canvas.

Same-slice closure receipts:
  - Gate #38 (coercion_cost_equals_complexity_by_construction):
    SATISFIED-BY-CONSTRUCTION at HEAD — Semiring<SymbolicCost> sole
    composition authority at src/v3/std/algebra.dag:181-188
  - Gate #39 (no_coercion_cost_dimension):
    SATISFIED-BY-CONSTRUCTION at HEAD — SymbolicCost 7-variant sole
    cost dimension; no parallel CoercionCost carrier per grep

Deferred gates (#37 / #40 / #70) cite follow-on cross-cutting
Behavior→primitive-identity wiring canvas at #2175.

Updates:
  - docs/r3-program-plan.md §10.3 row: α-narrow disposition + #2175 link
  - docs/r3-program-plan.md gate table rows #37-#40 + #70: status update
  - docs/v3-lens-capability-register.md cost.dag row: α-narrow receipt
  - src/v3/lenses/cost.dag header + deferred-discussion: replace
    5-option matrix with Director-ratified α disposition + 4 findings

Refs: #2141; closes-by-construction §1.8 #38 + #39; defers #37/#40/#70
to #2175.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(receipts): split SymbolicCost type vs composition-fn citations

Per cursor/composer-2 review on PR #2171 sha 0ce7c6f: the
src/v3/std/algebra.dag:181-188 range is the SymbolicCost type + 7
variants only; sequential/iterate composition fns live at lines
262-272. Citation slip fixed in 3 receipt locations to keep
navigable.

#2141 (parent issue) confirmed correct in cost.dag header — exploratory
clarification: PR is #2171, work-item issue is #2141.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Revert "docs(receipts): split SymbolicCost type vs composition-fn citations"

This reverts commit c5ed455.

* Revert "docs: T-CostLens-Composition α-narrow receipts — gates #38 + #39 closure"

This reverts commit 0ce7c6f.

* Revert "Revert "docs: T-CostLens-Composition α-narrow receipts — gates #38 + #39 closure""

This reverts commit 63d9d4f.

* docs(cost.dag): replace stale `~357 below` line pointer with named-section ref

Per codex review on PR #2171 sha 63d9d4f (now stacked on un-revert
commits c120bf1 + d4df2b0 → 63d9d4f): the line-number pointer
"~357 below" referenced a position that shifted after the
deferred-discussion insertion. Replaced with a named-section pointer
("Cost dimension data declaration / forward Lens boundary") that
doesn't decay under future edits.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens worker brief — ε supersession header (γ retained as context)

PR #2181 merged at eff426d ratifies ε path canonical-not-transitional
for cost composition. Brief was authored under γ scope (.dag-side
Lookup<SymbolicCost> composition). Add binding ε supersession header at
top; retain γ section as historical context per single-authority
discipline. cost.dag stays PROXY under ε; composition is Rust-side
(abstract SymbolicCost shape × per-primitive realization values).

Authority: Director ratification at #2181 #issuecomment-4401584012.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cost.dag): refresh status header for ε ratification (#2181)

Aligns in-file header with §10.3 row + capability-register row updates
already on main: BEHAVIORALLY PROXY → BEHAVIORALLY COMPLETE FOR
ABSTRACT-SHAPE per ε ratification at gunbc#2181 c#4401584012. Cost
factors as (target-agnostic abstract SymbolicCost — this file) ×
(target-specific concrete cost — Rust-side consumer per ε); concrete
wiring lives Rust-side, this file's substrate role unchanged.

Slice 0 of T-CostLens follow-on (#2141 ε scope per gunbc#2068
c#4402339074); Slice 1+ (Rust-side composition fn + test_runner
consumer + demo fixture) lands subsequently.

Refs: #2141; aligns with PR #2181 ε ratification.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Substrate T-CostLens-Composition behavioral completion (γ-ratified) — re

* fix(v3): Slice 1a fmt + sg0 ratchet + cost.dag header revert per BLOCKING review

Three fixes on PR #2194 (T-CostLens Slice 1a):

1. **cost.dag header** (BLOCKING per codex review on sha 8ff4ee9):
   reverted "BEHAVIORALLY COMPLETE FOR ABSTRACT-SHAPE" → "BEHAVIORALLY
   PROXY" to align with `docs/v3-lens-capability-register.md` cost.dag
   row (single-authority discipline per INVARIANTS P2). ε ratification
   context retained; status promotion deferred to canvas-tier consumer
   landings.

2. **fmt** (rustfmt diff on sha 6548ccf): collapsed
   `build_for_language` signature to one line; expanded
   `let Some(..) else { continue }` to multiline form per rustfmt
   default.

3. **sg0_census_test** (T-PB-A non-test SG-0 sub-ratchet): added
   `lens_cost_target_composition.rs` to EXPECTED_HAND_AUTHORED_NON_TEST
   with comment citing #2141 ε scope + #2181 ratification. New hand-Rust
   under Director-ratified ε scope authority; mirrors emit/rust_target.rs
   pattern (which is already in the list).

Refs: #2141, #2194, #2181 ratification.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cost.dag): clarify Slice 1a scope vs multi-slice plan per review

Per codex APPROVE_WITH_COMMENTS on PR #2194 sha 6548ccf: the header
phrasing "T-CostLens follow-on slice closes #37 + #40 + #70 via
Rust-side composition fn + test_runner consumer + demo fixture"
overstated this PR's scope — Slice 1a only lands RealizationCostTable
infra, not the consumer/runner/fixture.

Reframed to clarify it's the multi-slice PLAN (sequenced across separate
PRs) that closes the gates, not this single PR. Cites Slice 1a (PR
#2194) as the current commit + Slice 1b/2/3 as forthcoming.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* test(v3): Slice 1a builder smoke test against bootstrap rust.dag

Per Mgr disposition at gunbc#2068 c#4402516739: minimal 1a self-test
at the boundary (TESTING.md discipline — each slice self-testing at its
own boundary rather than relying on downstream slices to validate
upstream behavior). Exhaustive variant coverage lives in Slice 1b's
parameterized-fold tests.

Test asserts:
1. `build_for_language(dag, rust_id)` succeeds against bootstrap dag
2. Resulting table has at least one TypeRealization (non-empty)
3. `type_cost(Int)` returns Some(1) per src/v3/spec/rust.dag `rust_int`
   row (line ~118: `cost: 1`)

A 1a-broken table-builder caught here directly is a much shorter bisect
than waiting for Slice 1b regression.

Refs: #2141, #2194.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(v3): remove pub Default on RealizationCostTable per BLOCKING review

Per gpt-5-5-pro REQUEST_CHANGES on PR #2194 sha 6548ccf (BLOCKING #1
LAYER MODEL): public `Default` derive allowed downstream consumers to
construct an empty/ungrounded cost table without going through
`build_for_language` (substrate-derived facts could be fabricated;
fail-closed-at-substrate-consumer-boundary violated).

Removed `Default` derive; replaced internal `Self::default()` call site
with private `Self::empty()` initializer (module-private, used only by
`build_for_language`). Public construction now goes through the build
fn that requires `(Dag, DeclarationId)` inputs.

BLOCKING #2 (cost.dag status overstating live behavior) was already
addressed in commit 5a89f2f — reviewer was looking at sha 6548ccf
which predates that fix.

Refs: #2141, #2194.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(v3): drop pub *_count() L-8 lens-surface-gate violations

CI v3 job L-8 lens surface gate flagged `pub fn type_count() -> usize`
+ `callable_count` + `operator_count` + `behavior_count` as collapsing
typed carriers to primitives (`pub fn .*-> (usize|bool|i64)` rejected).

These methods existed only as test affordances; the smoke test now
asserts non-emptiness via the `type_cost(Int) == Some(1)` lookup
directly (a successful Some(1) implicitly proves table non-empty +
bootstrap row landed).

cost lookups (`type_cost`/`callable_cost`/`operator_cost`/`behavior_cost`)
return `Option<i64>` which dodges the L-8 regex (the lens-surface gate
matches `-> i64` directly, not `-> Option<i64>`).

Refs: #2141, #2194.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(v3): fail-closed on no-realization-costs language per BLOCKING review

Per gpt-5-5-pro REQUEST_CHANGES on PR #2194 sha 36e63d2 (LAYER MODEL +
Fail-Closed BLOCKING): `build_for_language` previously returned
`Ok(empty table)` when language_id matched zero realization rows —
fabricated-empty-table fail-closed contract violation. Downstream
consumers could see "plausible None lookups" instead of typed build
failure for bogus / unsupported language ids.

Added `BuildError::NoRealizationCostsForLanguage { language: DeclarationId }`
variant; post-loop check returns this error if all 4 maps are empty
(language id is bogus OR spec has no realization rows authored — both
bug-like states).

Negative test `build_for_non_language_id_fails_closed` covers the path:
passing the `Int` primitive's DeclarationId (not a LanguageSpec) yields
`NoRealizationCostsForLanguage` carrying the bogus id back.

Refs: #2141, #2194.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* ci: trigger fresh run for PR-body re-validation (SG-0 pairing line)

* fix(v3): mirror rust_target row-validity contract for parallel-acceptance fix

Per codex REQUEST_CHANGES on PR #2194 sha 9ed08bc (BLOCKING / INVARIANTS
P2 + modeling-discipline practices 5+6 single-authority metadata): my
builder accepted realization rows on weaker criteria than
emit/rust_target.rs:779+ (only checking language/target/op/cost,
ignoring carrier/is_copy/fields/strategy/parameters). Created parallel
acceptance authorities on one substrate boundary.

Added coarse-grained field-presence checks per category mirroring
rust_target's acceptance:
- TypeRealization: + carrier (String) + is_copy (Bool) + fields (present)
- CallableRealization: + strategy (present) + parameters (present)
- OperatorRealization: + carrier (String)
- BehaviorRealization: + carrier (String)

New helpers `require_field_string` / `require_field_bool` mirror the
rust_target patterns; `require_field_present` is a coarse-grained
presence check for fields whose internal shape is validated at
bootstrap-inhabitance time.

Refs: #2141, #2194.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* ci: trigger fresh run with SG-0 pairing class (b) Director-budget citation

* feat(v3): T-CostLens 1a.0 — declaration_by_name substrate accessor + delete rejected hand-Rust

Implements Director-ratified path (α) at gunbc#828 c#4402899692 +
Substrate Mgr re-dispatch at gunbc#2068 c#4402966788: introduce
`declaration_by_name(d: Dag, name: String) -> Declaration?` as `host`
substrate accessor (strict mirror of `declaration_by_id` at
substrate.dag:541-543), enabling `.dag`-tier consumers to acquire
substrate meta-type DeclarationIds at compile time.

Changes:
1. `src/v3/std/substrate.dag` — new `fn declaration_by_name` host fn
   below `declaration_by_id`; comment refresh at line 54 reflecting
   accessor now-landed.
2. `src/v3/spec/rust.dag` — `rust_declaration_by_name_accessor` carrier
   (`({p0}).declaration_by_name(&{p1}).cloned()`) + binding to
   `rust_language`. Mirrors declaration_by_id_binding_rust shape.
3. **Delete** `src/v3/compiler/src/lens_cost_target_composition.rs`
   (the 374-line stage0 hand-Rust addition NACK'd by Director at
   gunbc#828 c#4402795815 for P0 zero-hand-Rust violation).
4. Drop module wiring from lib.rs.
5. Drop file from sg0_census_test.rs EXPECTED_HAND_AUTHORED_NON_TEST
   (returns SG-0 §1.8 #8 ratchet to its prior position; net stage0
   hand-Rust delta = 0 per Director acceptance gate 4).

Sub-slice 1a.1 (consumer at .dag-tier in compiler.dag-or-analog)
follows in subsequent commit on this PR. Re-implementation will use
`declaration_by_name` to acquire `TypeRealization` /
`CallableRealization` etc. meta-type DeclarationIds for filtering
`d.declarations` by `meta_tag`.

Refs: #2141 (T-CostLens-Composition); #2181 ε ratification;
gunbc#828 c#4402899692 (α path ratification); gunbc#2068 c#4402966788
(re-dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore(v3): regen bootstrap_generated.rs after declaration_by_name addition

Operator-side bootstrap regen on PR #2194 1a.0 commit ec9ecd7 per
Substrate Mgr re-fire at gunbc#2068 c#4403961218 (cargo environment
fix broadcast). Propagates `fn declaration_by_name` substrate fn from
src/v3/std/substrate.dag into committed bootstrap snapshots.

Regen command: `cargo run -p v3-compiler --features bootstrap-regen-fresh
--bin regen_bootstrap` (per panic message authority); verify pass:
`regen_bootstrap --verify: committed snapshots match fresh compile.`

next_declaration_id 2453→2457 (matches the 4 new declarations from
substrate.dag fn + rust.dag SubstrateAccessorRealization +
SubstrateAccessorBinding + comment-refresh).

Refs: #2141, #2194; unblocks Operator-Bootstrap-Regen-Cargo-Shim-Wedge
named-token blocker on #2141 body.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 8, 2026
* docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 Variant-aware projection carrier canvas (#1947)

Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — same-slice prerequisite + section anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledger discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)

Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-Mgr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)

Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec8692): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — delete superseded canvas + name dissolution trigger for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)

cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — name dissolution trigger for DeclarationRef alias debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #2 + #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — consolidate split per-variant maps into single keyed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof canvas — 4-residual coproduct-dissolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authority map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85 — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof worker brief — γ ratified (2-variant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): descent_execution_proof — narrow EvidenceUnknown payload via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof — section-anchor cite for §10.3 row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> composition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scope-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition worker brief — γ ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Delete superseded T-CostLens canvas (worker brief is single live authority)

* docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demo (#1952) complexity-contract compile-error worker brief

Pre-staged execution brief per Director endorsement of T-LAS demos via direct
worker brief path (no canvas — design-lock at docs/design-lens-application-
surface.md specifies fixture shape verbatim at line 292).

7 same-slice acceptance gates: fixture program (O(n²) body + Enforce O(log n)
budget) + TestClaim assertion + diagnostic structural validation + no
regression on T-LBP cementing + bootstrap regen + clippy + §1.8 #92
advancement.

Hard prerequisites STOP-and-PING: T-LAS Slice A landed (gates #88-#91) AND
T-LBP complexity-lens BEHAVIORALLY COMPLETE (gate #79). Worker does not
author against partial substrate.

Sibling demos #1953 (CRDT cost) + #1954 (memory-peak cost) share the same
hard-prerequisite + TestClaim shape pattern — could dispatch as 3 sequential
PRs or single multi-demo PR (worker's call at dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demos #1953 + #1954 — cost-basis sibling worker brief

Pre-staged sibling brief covering both cost-basis demos (CRDT cost basis +
memory-peak cost basis) per Director endorsement of T-LAS demos via direct
worker-brief path. Single brief for two demos because they share:
- Hard-prerequisite pattern (T-LAS Slice A + T-LBP cost-lens BEHAVIORALLY COMPLETE)
- TestClaim + Diagnostic structural validation shape
- apply_lens(cost, ...) Enforce mode

Sibling of #1952 brief (complexity-contract compile-error). Worker's call at
dispatch on multi-demo PR vs sequential PRs (Mgr ratification needed if going
multi-demo).

#1953 (CRDT) substrate per design §4.2 + cost-basis-declaration audit at
docs/audit/t-user-authored-cost-basis-discipline-worked-examples.md.
#1954 (memory-peak) substrate per design §4.3; STOP-and-PING if
Dimension<SymbolicCost> substrate (deferred to Dimensions sub-lane per Director
ratification at gunbc#828 #issuecomment-4395691775) not yet landed.

6 same-slice acceptance gates per demo + same STOP-and-PING discipline as #1952.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens — update Sub-issue from #1957 to #2141 (post-surgical-recreate)

PM executed Director's surgical-recreate ratification (gunbc#828
#issuecomment-4397693699) at 17:54:43Z: closed #1957, created fresh #2141 to
trigger pollAutoSpawn fresh-creation path. Worker fierce-ram-21 (#2153) spawned
on #2141.

1-line brief update per Director's queued-action commitment: brief now
references #2141 + cites surgical-recreate authority. #1957 closed-as-superseded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context canvas (β-extended substrate-shape question)

Director α-revised supersession at gunbc#828 #issuecomment-4400920572 elevated
β-extended path (introduce first-precedent .dag-side fold-over-realization-rows
+ name active-target authority shape) from slice-tier to canvas-tier.

Authored per Q-PAFS template:
- Substrate-state at HEAD grep-verified (Lens<C>.read no target-context;
  zero .dag-side fold-over-realizations precedent; 15+ lens instances using
  generic Lens<C>)
- Binary question: should .dag-side lenses receive target-context for
  target-keyed reading?
- Options matrix: (i) LanguageSpec param to fold; (ii) per-target lens
  instances [parallel-representation debt]; (iii) global accessor [REJECTED
  global-state anti-pattern]
- Mgr provisional preference: (i)
- Cross-cutting: cost.dag load-bearing; emission_provenance.dag secondary;
  other 13+ lenses target-agnostic

Framework discipline anchors per Director corrections:
- feedback_same_slice_dissolution_discipline
- feedback_parallel_representation_debt
- feedback_abstraction_layering (sibling canvas)

Sibling canvas (ε path): q-cost-composition-layering-canvas.md authoring
follows. Both canvases together address deeper cross-cutting axis: does
target-context belong .dag-side (β-extended) or emit-side (ε)?

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Cost-Composition-Layering canvas (ε substrate-shape question)

Sibling canvas to q-lens-target-context-canvas.md. Director α-revised
supersession at gunbc#828 #issuecomment-4400920572 elevated ε path (Rust-side
cost-composition wiring; preserves cost.dag PROXY) from slice-tier to
canvas-tier.

Authored per Q-PAFS template:
- Factoring claim: cost = (target-agnostic-shape SymbolicCost algebra) ×
  (target-specific-values per-primitive realization-cost data loaded Rust-side)
- Test against feedback_abstraction_layering (Director-named anchor at
  gunbc#828 c#4400921658): pure objective concepts × language-agnostic
  LanguageSpec × emit-side composition. Compliance test for each layer.
- Pro factoring (ε structurally honest): SymbolicCost algebra is target-
  agnostic at HEAD; Rust-side composition is natural home; #38/#39 substrate-
  already-aligned per Slice 1 finding.
- Con factoring (ε is parallel-representation debt): N parallel Rust-side
  compositions if multiple lenses need target-context; lens-framework
  abstraction stops at substrate boundary; future lenses hit same dilemma.

Mgr provisional reading: factoring honest for COST specifically; NOT
generalizable. ε right framing IF cost is the singular need + factoring
holds. If N>1 target-context-needing lenses surface, β-extended (option
(i) from sibling canvas) becomes the right path.

Director ratification ask: 3-way choice
  (ε) Cost-specific Rust-side composition; preserves cost.dag PROXY
  (β-extended option (i)) Lens<C> refactor for LanguageSpec parameter
  (both sequenced) ε now for cost; β-extended later if N>1

Framework discipline anchors:
- feedback_abstraction_layering (Director-named for this canvas)
- feedback_parallel_representation_debt
- feedback_same_slice_dissolution_discipline

Canvas-pair complete; sibling canvas + this canvas address the deeper
cross-cutting axis: target-context belongs .dag-side (β-extended) or
emit-side (ε)? Director ratification across both informs T-CostLens
follow-on slice + downstream lens architecture.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: ε ratified canonical for cost; β-extended deferred to N=2 — gate updates

Director ratification at #2181 #issuecomment-... :
- (ε) RATIFIED standalone for cost composition (canonical-not-transitional)
- (β-extended option (i)) DEFERRED to N=2 trigger event (second lens with
  target-context need beyond cost)
- ("both sequenced") REJECTED as bridge-with-named-dissolution anti-pattern

Same-slice acceptance gates landed:

1. Q-Cost-Composition-Layering canvas: status updated from "ratification
   needed" → "Director-RATIFIED 2026-05-07 (ε standalone; canonical-not-
   transitional); PROPOSAL maturation pending"
2. Q-Lens-Target-Context canvas: status updated from "ratification needed"
   → "DRAFT/DEFERRED 2026-05-07; reopens on N=2 trigger event" (second lens
   with substantive target-context need; emission_provenance most likely
   candidate per cross-cutting analysis §3)
3. r3-program-plan.md gate-table rows #37 + #40 + #70: ε path ratified;
   close via Rust-side composition reading abstract SymbolicCost × per-
   primitive realization-cost in T-CostLens follow-on slice
4. r3-program-plan.md §10.3 T-CostLens-Composition row: ε ratified for
   #37/#40/#70; β-extended deferred per N=2 trigger
5. v3-lens-capability-register.md cost.dag row: ε disposition cited; #2175
   continues as cross-cutting umbrella tracker

Closed-system disposition per Director: if N=2 condition never fires,
β-extended never fires — structurally correct under closed-system design.

Framework discipline anchors honored:
- feedback_abstraction_layering: ε respects layering (objective concepts
  pure; target-specific values flow at emit time per Layer-3 honesty test)
- feedback_parallel_representation_debt: bounded to N=1; reopens at N=2
- feedback_same_slice_dissolution_discipline: ε ratified canonical, not
  transitional
- feedback_construction_over_ratchets: substrate-shape question answered
  structurally
- feedback_substrate_principle_audit: substrate-fact authored at canvas-
  tier; ratification follows P1 procedure

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvas inventory grounded in live src/v3/lenses/ registry

codex BLOCKING at #2181 (sha 00551a8): Q-Lens-Target-Context
canvas inventory was "copied from expected lens set instead of live
src/v3/lenses/ registry"; emission_provenance trigger references not
grounded in live file content.

Same shape of error as 3 prior BLOCKING reversals (Q-Reification, S5
DeclarationRef, T-CostLens merge-content). Substrate-state-grep is being
treated as retrospective-correction rather than prerequisite. Tightening:
this is the 4th occurrence; should be hard-prerequisite-discipline going
forward.

Fixes:

1. Q-Lens-Target-Context inventory section: replaced approximate "15+
   lens instances" framing with exact `ls`-grep registry (15 .dag files
   listed by name), notes infer_helpers + lower_helpers are helper
   modules authoring shared structural fns rather than top-level lens
   instances.

2. emission_provenance.dag analysis grounded in HEAD file status header:
   STATUS = STRUCTURALLY TERMINAL; LENS-INSTANCE FIXTURE-BOUND; BEHAVIORALLY
   DEFERRED. `read` body is fail-closed Empty stub. Lens does NOT currently
   read target-context inside fold; producer-side instrumentation records
   target-specific entries consumed via standard framework. Reframed as
   "ungrounded at HEAD" rather than "POSSIBLY target-context need" —
   re-evaluates at producer-wiring landing.

3. Net finding: N=1 confirmed at HEAD (cost.dag only); N=2 is empirically
   open pending lens-completion cycles, NOT pre-claimable.

Plus non-blocking improvement: Q-Cost-Composition-Layering line 9 stale
`#issuecomment-...` placeholder replaced with concrete ratification
comment id `#issuecomment-4401584012`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): fix Director-ratification-ask typo + #37 gate-id clarification footnote

cursor APPROVE_WITH_COMMENTS at #2181 (sha 4209eb7) flagged 2
NON-BLOCKING items + 1 exploratory:

1. (NON-BLOCKING) Q-Cost-Composition-Layering line 69: `## Directorratification ask` → `## Director ratification ask` (whitespace typo)
2. (NON-BLOCKING) Q-Cost-Composition-Layering line 9 placeholder `#issuecomment-...`: ALREADY ADDRESSED in commit `db88b1004` (replaced with `#issuecomment-4401584012`)
3. (Exploratory) Gate #37 id `cost_lens_reads_target_realization` framing implies .dag lens body performs realization read; per ε ratification it's Rust-side composition consumer. Added clarifying footnote noting gate-id retention + Rust-side closure path; rename candidate post-follow-on-slice landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — absorb PM canvas-review concerns 1-3

Director relayed PM canvas review at #2068 c#4401627536:

Concern 1 (RESOLVED via grep-verify): empirical N=1 confirmation. PM ran
`grep -lc 'TypeRealization|CallableRealization|MethodTemplateContract|
target_realization|realization_cost|LanguageSpec' src/v3/lenses/*.dag`;
only cost.dag has 3 hits, all 14 others have 0 refs (including
emission_provenance.dag which I'd previously framed speculatively).

Net-finding §3 updated with grep result inline + "N=1 empirically grounded"
framing replacing speculative "secondary candidate" language. Empirical
basis for DEFERRED β-extended disposition strengthened.

Concern 2 (Option (ii) multiplier framing): per-target lens instances
replicate the entire Lens<C> authoring surface — N×M × 4 (carrier + monoid
sequential + branch + iterate) authoring overhead. Updated Con bullet to
reflect the multiplier explicitly: 3 targets × 1 cost lens × 4 = 12 authored
fns; grows to 36 if 3 lenses need target-context. Cites
feedback_parallel_representation_debt as the P2 framing.

Concern 3 (Option (i) threading cost quantification): replaced narrative
"threading cost is real but manageable" with quantified breakdown — ~15
signature changes + 14 ignore-parameter patterns + 1 consumer + cementing-
test revalidation. Helps future Director ratification at N=2 trigger event.

All 3 amendments are docs-only refinements; ε ratification at gunbc#2181
c#4401584012 unchanged. Strengthens canvas as durable substrate-shape
decision record.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvases — collapse stale ratification-ask sections post-ratification

codex BLOCKING at #2181 (sha be9a9c9): both canvases had stale
"Director ratification ask" sections after status headers were updated to
RATIFIED/DEFERRED. Per INVARIANTS P1 "Documentation Describes Live State" —
canvas internally presented both settled and unsettled authority.

Fixes:

1. Q-Cost-Composition-Layering line 69-76: "Director ratification ask"
   section collapsed to "Director ratification (RECEIVED 2026-05-07)" with
   ε ratified, β-extended deferred, "both sequenced" rejected. Three options
   recorded as historical with ratification cite. Eliminates the rejected
   "both, sequenced" line that conflicted with status-header "canonical-not-
   transitional" framing.

2. Q-Lens-Target-Context line 131-136: "Director ratification ask" section
   collapsed to "Director disposition (DEFERRED 2026-05-07; reopens on N=2
   trigger event)". Original ratification asks recorded as FROZEN; revisit
   at N=2 trigger event with then-current substrate-state grep. Eliminates
   live-now-ratify framing that conflicted with status-header DEFERRED.

Both canvases now single live authority — RATIFIED/DEFERRED dispositions,
no internal ratification-ask drift. Future re-ratification (Q-Lens-Target-
Context at N=2 trigger) refreshes options matrix at that point per
substrate-state-honesty discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — separate live N=1 from reopen-only future N=2

openai-pro APPROVE_WITH_COMMENTS at #2181 (sha be9a9c9): canvas
line 127 mixed live N=1 authority with speculative N=2 candidate in one
current-state cost count.

Per P1 Documentation Describes Live State + P2 single-authority metadata:
the live count at HEAD is `cost × 3 targets = 3 per-target instances` (× 4
authoring-multiplier per Option (ii) Con = 12 fns). The `emission_provenance
× 3` figure is a reopen-only future scenario that materializes only if
emission_provenance becomes the second real target-context lens at producer-
wiring landing time.

Updated to separate the two clearly: live count + reopen-only future
scenario marked separately. Aligns with the grep-verified N=1 finding
established earlier in canvas §3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): T-CostLens worker brief — ε supersession header (γ retained as context)

PR #2181 merged at eff426d ratifies ε path canonical-not-transitional
for cost composition. Brief was authored under γ scope (.dag-side
Lookup<SymbolicCost> composition). Add binding ε supersession header at
top; retain γ section as historical context per single-authority
discipline. cost.dag stays PROXY under ε; composition is Rust-side
(abstract SymbolicCost shape × per-primitive realization values).

Authority: Director ratification at #2181 #issuecomment-4401584012.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Complexity-Composition-Layering canvas — DRAFT (factoring tested, ε precedent does NOT apply)

Director authorized canvas authoring at #828 c#4402669133 as
parallel structure to Q-Cost-Composition-Layering (ε RATIFIED). Substrate-
grep on src/v3/lenses/complexity.dag at HEAD shows the factoring claim
DIFFERS from cost-lens:

- Cost-lens needed (target-agnostic shape × target-specific values)
  factoring → Rust-side composition (ε)
- Complexity-lens has NO target-specific axis; output is structural
  property of DAG topology + algebra-instance composition; substrate-
  native fully-on-.dag-side completion

Mgr provisional reading: ε precedent does NOT apply; complexity-lens
BEHAVIORAL COMPLETION is direct slice-tier substrate authoring (carrier
introduction follows SymbolicCost precedent + T-E-P P1 carrier
consumption). Director ratification ask: Q1 (factoring finding correct),
Q2 (slice-tier directly bypassing canvas), Q3 (fresh worker pin).

Cross-Mgr: Verification Mgr (#2075) pinged on v2-oracle snapshot capture
status (cross-cutting prerequisite for #1950/#1951 cementing dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LBP complexity-lens substrate-completion worker brief (Q1/Q2/Q3 RATIFIED)

Pre-authored brief for complexity-lens BEHAVIORAL COMPLETION substrate
work per Director Q1/Q2/Q3 ratification at #828 c#4402714255.

Three deliverables: carrier introduction (ComplexityCost / WorkSpan /
AsymptoticClass following SymbolicCost precedent) + lens widening
(complexity.dag PROXY → COMPLETE) + T-E-P P1 carrier consumption
(DescentEvidence / CallPattern / SubValueRelation for asymptotic
classification of recursive-call behavior).

Indirect-variant dependency surfaced as worker-grep concern at slice-
authoring time (T-E-P P1 Slice 5+ pending; eager-bat-178 stream).

Cementing test (#1950) is separate downstream brief; v2-oracle snapshot
ownership pending Q4 cross-Mgr ratification.

Worker pin: fresh-pool pick at dispatch time (NOT eager-bat-178 per
Director Q3 framing; NOT fierce-ram-21 busy with cost-lens ε).

Same-window-dispatch discipline applies post-canvas-merge (PR #2197).

Pre-authored vs pre-known discipline applied per
feedback_pre_known_vs_pre_authored_briefs.md memorialized 2026-05-08.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): rewrite complexity-lens brief consuming live design authority (codex BLOCKING fix)

Codex BLOCKING (3 findings) at #2199 sha 7a8bb6d:
1. Brief authored against missing canvas instead of reconciling with
   docs/design-complexity-lens-behavioral-completeness.md (which exists
   at HEAD with comprehensive substrate spec)
2. Producer coverage treated as optional corpus scope; should be hard
   T-E-P-Producer-Broadening prerequisite
3. Stale/non-in-repo planning authority cited; should be r3-structure.md
   row 146 (T-LBP slice 1)

All three BLOCKING findings VALID — substrate-grep-before-authoring
discipline failure on my part (feedback_substrate_grep_before_authoring
already memorialized; violated own discipline).

Rewrite delegates carrier shape, dimension wiring, and consumer rewrite
to live design doc §§1.1-1.6 verbatim:
- §1.1 SymbolicCost — already at algebra.dag; no change
- §1.2 SizeVariable — display_name enrichment
- §1.3 work_dimension + span_dimension — two AnalysisDimension instances
- §1.4 AsymptoticClass + BoundedLattice instance
- §1.5 Certainty (cost-aware composition; no lattice)
- §1.6 cost_bound_to_symbolic projection
- §1.7 ComplexitySummary record + lens widening

T-E-P P1 hard prerequisite per design's authority discipline + r3-
structure.md row 146; STOP-and-PING if T-E-P P1 not COMPLETE at slice
authoring time. Authority cites updated to live r3-structure.md row 146.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas — DRAFT (canvas-tier P1 procedure per Q6 RATIFIED)

Director Q6 RATIFIED canvas-tier-required at #828 c#4403163639
for PerfWithinBaseline TestPredicate variant authoring. Three substantive
substrate-shape questions resolved:

Q1 baseline shape: (a) literal-Int rejected as strict-mirror-of-CostBounded
defeats semantic load; (b) DeclarationRef-to-stored-data composes
LensOutputEquals + data X: SymbolicCost precedent at HEAD; (c) runtime-
fixture-injection over-authors. Mgr lean (b).

Q2 ComparisonOp composition: (i) reuse existing ComparisonOp via test-
runner-side resolution matches LensOutputEquals path; (ii) new relative-
op-set introduces parallel-representation debt. Mgr lean (i).

Q3 baseline-storage scope: (α) in-scope slice authors example data; (β)
out-of-scope variant-only slice + PB consumer authors baseline data
matches existing layering. Mgr lean (β).

Combined Mgr lean: Q1(b) + Q2(i) + Q3(β) — variant authored as
compositional extension; baseline-storage is PB consumer-tier work.

Cross-Mgr: PB Mgr #2138 worker (crisp-swift-433) holds dispatch on #2204
land; T-Tier3-Dissolution #2085 R-4 prereq encoded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas REVISED (supersedes wrong-shape original)

Director disposition at #828 c#4403265220 authorized
supersession after BLOCKING at PR #2209 c#4403246233 verified VALID:
original canvas conflated symbolic SymbolicCost (cost-lens substrate)
with wall-clock measured median/p99 baseline (T-Tier3 perf gate
substrate per docs/r3-structure.md:225 + :461 Director-locked 2026-04-28).

Revised canvas frames as two-path ratification:
- P1 author full perf-budget substrate in-R3 (multi-slice; pattern-5
  genuinely-novel substrate-fact-introduction)
- P2 explicitly post-R3 per Director-locked recommendation (zero in-R3
  effort; structural close per r3-structure.md:461 'R3 deliverable is
  structural close; perf is downstream')

Mgr lean: P2 — Director-locked recommendation explicit; trigger-
condition ('someone authors perf-budget claim with concrete numbers
and tooling') not met; R3 horizon constraint argues against multi-
slice perf-budget substrate adding to 5-orthogonal-dependency picture.

Original canvas at q-perf-within-baseline-canvas.md retained with
SUPERSEDED-BY header per durable-decision-record discipline.

5th discipline-failure of 2026-05-08 cycle: substrate-grep verified
substrate-precedent but missed consumer-side requirement at canonical
authority doc; Director self-flagged symmetric two-axis verification
gap; canvas-finding-taxonomy needs precondition 'consumer-side
requirement grep-verified at canonical authority doc'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas-revised — correct trigger-condition framing per Director c#4403297623

Director caught second-axis grep failure on revised canvas: my P2
reasoning #1 ("path-trigger condition for P1 is not met") was
structurally wrong. Existing tooling at HEAD substantially meets the
Director-locked 2026-04-28 trigger-condition ("someone authors the
perf-budget claim with concrete numbers and tooling"):

- docs/briefs/r3-pb-tier3-perf-budget-worker.md
- docs/audit/c1-tier3-perf-budget-readiness-matrix.md
- src/v3/compiler/benches/tier3_mirror_perf.rs
- docs/audit/c1-tier3-baseline-capture-procedure.md
- docs/audit/c1-r3-canonical-bench-host-decision-matrix.md

Plus thresholds (≤2× median, ≤5× p99) + capture discipline (N=3 min,
N=5 preferred) + canonical bench host option matrix.

P1 is bridging existing tooling to substrate (compositional-extension),
NOT multi-slice greenfield genuinely-novel pattern-5 as originally
framed. Smaller scope than canvas-finding-taxonomy pattern 5 implies.

Path-call genuinely depends on PB Mgr's R-3 (canonical CI bench host)
+ R-7 (tier3_baseline.json baseline-capture path) decisions per their
audit response at c#4403059897. Path-call DEFERRED to cross-Mgr
coordination outcome with PB Mgr (#2074); Substrate Mgr surfaces with
corrected framing this turn.

Sixth discipline-failure of cycle (mine, second-axis grep gap on
existing-tooling state); same-class as Director's first-axis grep gap
on consumer-side requirement at the prior turn. Memorialized as
two-axis verification discipline anchor.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-ValueBody-Drift-Resolution canvas — DRAFT (codegen-generation lean)

D1 substrate-shape question per Q-ValueBody-Isomorphism RATIFIED at
#828 c#4403972737. Variant-inventory readiness input from
PR #2218 (merged 2026-05-08) confirms drift: Rust 5 variants vs
substrate 3 constructors; asymmetry on Scalar+List Rust-only +
Map payload-parity-with-semantic-gap.

Two-axis verification at HEAD:
- Substrate-precedent: codegen tooling exists (regen_bootstrap_emit;
  5 _generated.rs files; regen_bootstrap binary). Pattern-3 strict-
  mirror codegen extension applies; no pattern-5 P1 procedure.
- Consumer-side requirement: V1 worker brief explicitly names mirror-
  parity-vs-codegen-generation as D1 path-pair.

Mgr lean: (b) codegen-generation. Path (a) mirror-parity perpetuates
parallel-representation debt; (b) dissolves the dual-taxonomy class
by construction (substrate canonical, Rust codegens). Map dup-key gap
handled via (ii) Rust-side post-codegen wrapping (substrate stays
minimal).

Director ratification ask: D1 (b) + D1-followup (ii).

Carrier slice path post-ratification: extend regen_bootstrap_emit;
add Scalar+List constructors to substrate; regen + remove hand-Rust
enum; handle Map dup-key per ratified followup. Worker pin fresh-pool
per same-window-dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 8, 2026
…cite (#2226)

* docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 Variant-aware projection carrier canvas (#1947)

Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — same-slice prerequisite + section anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledger discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)

Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-Mgr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)

Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec8692): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — delete superseded canvas + name dissolution trigger for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)

cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — name dissolution trigger for DeclarationRef alias debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #2 + #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — consolidate split per-variant maps into single keyed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof canvas — 4-residual coproduct-dissolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authority map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85 — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof worker brief — γ ratified (2-variant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): descent_execution_proof — narrow EvidenceUnknown payload via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof — section-anchor cite for §10.3 row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> composition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scope-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition worker brief — γ ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Delete superseded T-CostLens canvas (worker brief is single live authority)

* docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demo (#1952) complexity-contract compile-error worker brief

Pre-staged execution brief per Director endorsement of T-LAS demos via direct
worker brief path (no canvas — design-lock at docs/design-lens-application-
surface.md specifies fixture shape verbatim at line 292).

7 same-slice acceptance gates: fixture program (O(n²) body + Enforce O(log n)
budget) + TestClaim assertion + diagnostic structural validation + no
regression on T-LBP cementing + bootstrap regen + clippy + §1.8 #92
advancement.

Hard prerequisites STOP-and-PING: T-LAS Slice A landed (gates #88-#91) AND
T-LBP complexity-lens BEHAVIORALLY COMPLETE (gate #79). Worker does not
author against partial substrate.

Sibling demos #1953 (CRDT cost) + #1954 (memory-peak cost) share the same
hard-prerequisite + TestClaim shape pattern — could dispatch as 3 sequential
PRs or single multi-demo PR (worker's call at dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demos #1953 + #1954 — cost-basis sibling worker brief

Pre-staged sibling brief covering both cost-basis demos (CRDT cost basis +
memory-peak cost basis) per Director endorsement of T-LAS demos via direct
worker-brief path. Single brief for two demos because they share:
- Hard-prerequisite pattern (T-LAS Slice A + T-LBP cost-lens BEHAVIORALLY COMPLETE)
- TestClaim + Diagnostic structural validation shape
- apply_lens(cost, ...) Enforce mode

Sibling of #1952 brief (complexity-contract compile-error). Worker's call at
dispatch on multi-demo PR vs sequential PRs (Mgr ratification needed if going
multi-demo).

#1953 (CRDT) substrate per design §4.2 + cost-basis-declaration audit at
docs/audit/t-user-authored-cost-basis-discipline-worked-examples.md.
#1954 (memory-peak) substrate per design §4.3; STOP-and-PING if
Dimension<SymbolicCost> substrate (deferred to Dimensions sub-lane per Director
ratification at gunbc#828 #issuecomment-4395691775) not yet landed.

6 same-slice acceptance gates per demo + same STOP-and-PING discipline as #1952.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens — update Sub-issue from #1957 to #2141 (post-surgical-recreate)

PM executed Director's surgical-recreate ratification (gunbc#828
#issuecomment-4397693699) at 17:54:43Z: closed #1957, created fresh #2141 to
trigger pollAutoSpawn fresh-creation path. Worker fierce-ram-21 (#2153) spawned
on #2141.

1-line brief update per Director's queued-action commitment: brief now
references #2141 + cites surgical-recreate authority. #1957 closed-as-superseded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context canvas (β-extended substrate-shape question)

Director α-revised supersession at gunbc#828 #issuecomment-4400920572 elevated
β-extended path (introduce first-precedent .dag-side fold-over-realization-rows
+ name active-target authority shape) from slice-tier to canvas-tier.

Authored per Q-PAFS template:
- Substrate-state at HEAD grep-verified (Lens<C>.read no target-context;
  zero .dag-side fold-over-realizations precedent; 15+ lens instances using
  generic Lens<C>)
- Binary question: should .dag-side lenses receive target-context for
  target-keyed reading?
- Options matrix: (i) LanguageSpec param to fold; (ii) per-target lens
  instances [parallel-representation debt]; (iii) global accessor [REJECTED
  global-state anti-pattern]
- Mgr provisional preference: (i)
- Cross-cutting: cost.dag load-bearing; emission_provenance.dag secondary;
  other 13+ lenses target-agnostic

Framework discipline anchors per Director corrections:
- feedback_same_slice_dissolution_discipline
- feedback_parallel_representation_debt
- feedback_abstraction_layering (sibling canvas)

Sibling canvas (ε path): q-cost-composition-layering-canvas.md authoring
follows. Both canvases together address deeper cross-cutting axis: does
target-context belong .dag-side (β-extended) or emit-side (ε)?

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Cost-Composition-Layering canvas (ε substrate-shape question)

Sibling canvas to q-lens-target-context-canvas.md. Director α-revised
supersession at gunbc#828 #issuecomment-4400920572 elevated ε path (Rust-side
cost-composition wiring; preserves cost.dag PROXY) from slice-tier to
canvas-tier.

Authored per Q-PAFS template:
- Factoring claim: cost = (target-agnostic-shape SymbolicCost algebra) ×
  (target-specific-values per-primitive realization-cost data loaded Rust-side)
- Test against feedback_abstraction_layering (Director-named anchor at
  gunbc#828 c#4400921658): pure objective concepts × language-agnostic
  LanguageSpec × emit-side composition. Compliance test for each layer.
- Pro factoring (ε structurally honest): SymbolicCost algebra is target-
  agnostic at HEAD; Rust-side composition is natural home; #38/#39 substrate-
  already-aligned per Slice 1 finding.
- Con factoring (ε is parallel-representation debt): N parallel Rust-side
  compositions if multiple lenses need target-context; lens-framework
  abstraction stops at substrate boundary; future lenses hit same dilemma.

Mgr provisional reading: factoring honest for COST specifically; NOT
generalizable. ε right framing IF cost is the singular need + factoring
holds. If N>1 target-context-needing lenses surface, β-extended (option
(i) from sibling canvas) becomes the right path.

Director ratification ask: 3-way choice
  (ε) Cost-specific Rust-side composition; preserves cost.dag PROXY
  (β-extended option (i)) Lens<C> refactor for LanguageSpec parameter
  (both sequenced) ε now for cost; β-extended later if N>1

Framework discipline anchors:
- feedback_abstraction_layering (Director-named for this canvas)
- feedback_parallel_representation_debt
- feedback_same_slice_dissolution_discipline

Canvas-pair complete; sibling canvas + this canvas address the deeper
cross-cutting axis: target-context belongs .dag-side (β-extended) or
emit-side (ε)? Director ratification across both informs T-CostLens
follow-on slice + downstream lens architecture.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: ε ratified canonical for cost; β-extended deferred to N=2 — gate updates

Director ratification at #2181 #issuecomment-... :
- (ε) RATIFIED standalone for cost composition (canonical-not-transitional)
- (β-extended option (i)) DEFERRED to N=2 trigger event (second lens with
  target-context need beyond cost)
- ("both sequenced") REJECTED as bridge-with-named-dissolution anti-pattern

Same-slice acceptance gates landed:

1. Q-Cost-Composition-Layering canvas: status updated from "ratification
   needed" → "Director-RATIFIED 2026-05-07 (ε standalone; canonical-not-
   transitional); PROPOSAL maturation pending"
2. Q-Lens-Target-Context canvas: status updated from "ratification needed"
   → "DRAFT/DEFERRED 2026-05-07; reopens on N=2 trigger event" (second lens
   with substantive target-context need; emission_provenance most likely
   candidate per cross-cutting analysis §3)
3. r3-program-plan.md gate-table rows #37 + #40 + #70: ε path ratified;
   close via Rust-side composition reading abstract SymbolicCost × per-
   primitive realization-cost in T-CostLens follow-on slice
4. r3-program-plan.md §10.3 T-CostLens-Composition row: ε ratified for
   #37/#40/#70; β-extended deferred per N=2 trigger
5. v3-lens-capability-register.md cost.dag row: ε disposition cited; #2175
   continues as cross-cutting umbrella tracker

Closed-system disposition per Director: if N=2 condition never fires,
β-extended never fires — structurally correct under closed-system design.

Framework discipline anchors honored:
- feedback_abstraction_layering: ε respects layering (objective concepts
  pure; target-specific values flow at emit time per Layer-3 honesty test)
- feedback_parallel_representation_debt: bounded to N=1; reopens at N=2
- feedback_same_slice_dissolution_discipline: ε ratified canonical, not
  transitional
- feedback_construction_over_ratchets: substrate-shape question answered
  structurally
- feedback_substrate_principle_audit: substrate-fact authored at canvas-
  tier; ratification follows P1 procedure

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvas inventory grounded in live src/v3/lenses/ registry

codex BLOCKING at #2181 (sha 00551a8): Q-Lens-Target-Context
canvas inventory was "copied from expected lens set instead of live
src/v3/lenses/ registry"; emission_provenance trigger references not
grounded in live file content.

Same shape of error as 3 prior BLOCKING reversals (Q-Reification, S5
DeclarationRef, T-CostLens merge-content). Substrate-state-grep is being
treated as retrospective-correction rather than prerequisite. Tightening:
this is the 4th occurrence; should be hard-prerequisite-discipline going
forward.

Fixes:

1. Q-Lens-Target-Context inventory section: replaced approximate "15+
   lens instances" framing with exact `ls`-grep registry (15 .dag files
   listed by name), notes infer_helpers + lower_helpers are helper
   modules authoring shared structural fns rather than top-level lens
   instances.

2. emission_provenance.dag analysis grounded in HEAD file status header:
   STATUS = STRUCTURALLY TERMINAL; LENS-INSTANCE FIXTURE-BOUND; BEHAVIORALLY
   DEFERRED. `read` body is fail-closed Empty stub. Lens does NOT currently
   read target-context inside fold; producer-side instrumentation records
   target-specific entries consumed via standard framework. Reframed as
   "ungrounded at HEAD" rather than "POSSIBLY target-context need" —
   re-evaluates at producer-wiring landing.

3. Net finding: N=1 confirmed at HEAD (cost.dag only); N=2 is empirically
   open pending lens-completion cycles, NOT pre-claimable.

Plus non-blocking improvement: Q-Cost-Composition-Layering line 9 stale
`#issuecomment-...` placeholder replaced with concrete ratification
comment id `#issuecomment-4401584012`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): fix Director-ratification-ask typo + #37 gate-id clarification footnote

cursor APPROVE_WITH_COMMENTS at #2181 (sha 4209eb7) flagged 2
NON-BLOCKING items + 1 exploratory:

1. (NON-BLOCKING) Q-Cost-Composition-Layering line 69: `## Directorratification ask` → `## Director ratification ask` (whitespace typo)
2. (NON-BLOCKING) Q-Cost-Composition-Layering line 9 placeholder `#issuecomment-...`: ALREADY ADDRESSED in commit `db88b1004` (replaced with `#issuecomment-4401584012`)
3. (Exploratory) Gate #37 id `cost_lens_reads_target_realization` framing implies .dag lens body performs realization read; per ε ratification it's Rust-side composition consumer. Added clarifying footnote noting gate-id retention + Rust-side closure path; rename candidate post-follow-on-slice landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — absorb PM canvas-review concerns 1-3

Director relayed PM canvas review at #2068 c#4401627536:

Concern 1 (RESOLVED via grep-verify): empirical N=1 confirmation. PM ran
`grep -lc 'TypeRealization|CallableRealization|MethodTemplateContract|
target_realization|realization_cost|LanguageSpec' src/v3/lenses/*.dag`;
only cost.dag has 3 hits, all 14 others have 0 refs (including
emission_provenance.dag which I'd previously framed speculatively).

Net-finding §3 updated with grep result inline + "N=1 empirically grounded"
framing replacing speculative "secondary candidate" language. Empirical
basis for DEFERRED β-extended disposition strengthened.

Concern 2 (Option (ii) multiplier framing): per-target lens instances
replicate the entire Lens<C> authoring surface — N×M × 4 (carrier + monoid
sequential + branch + iterate) authoring overhead. Updated Con bullet to
reflect the multiplier explicitly: 3 targets × 1 cost lens × 4 = 12 authored
fns; grows to 36 if 3 lenses need target-context. Cites
feedback_parallel_representation_debt as the P2 framing.

Concern 3 (Option (i) threading cost quantification): replaced narrative
"threading cost is real but manageable" with quantified breakdown — ~15
signature changes + 14 ignore-parameter patterns + 1 consumer + cementing-
test revalidation. Helps future Director ratification at N=2 trigger event.

All 3 amendments are docs-only refinements; ε ratification at gunbc#2181
c#4401584012 unchanged. Strengthens canvas as durable substrate-shape
decision record.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvases — collapse stale ratification-ask sections post-ratification

codex BLOCKING at #2181 (sha be9a9c9): both canvases had stale
"Director ratification ask" sections after status headers were updated to
RATIFIED/DEFERRED. Per INVARIANTS P1 "Documentation Describes Live State" —
canvas internally presented both settled and unsettled authority.

Fixes:

1. Q-Cost-Composition-Layering line 69-76: "Director ratification ask"
   section collapsed to "Director ratification (RECEIVED 2026-05-07)" with
   ε ratified, β-extended deferred, "both sequenced" rejected. Three options
   recorded as historical with ratification cite. Eliminates the rejected
   "both, sequenced" line that conflicted with status-header "canonical-not-
   transitional" framing.

2. Q-Lens-Target-Context line 131-136: "Director ratification ask" section
   collapsed to "Director disposition (DEFERRED 2026-05-07; reopens on N=2
   trigger event)". Original ratification asks recorded as FROZEN; revisit
   at N=2 trigger event with then-current substrate-state grep. Eliminates
   live-now-ratify framing that conflicted with status-header DEFERRED.

Both canvases now single live authority — RATIFIED/DEFERRED dispositions,
no internal ratification-ask drift. Future re-ratification (Q-Lens-Target-
Context at N=2 trigger) refreshes options matrix at that point per
substrate-state-honesty discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — separate live N=1 from reopen-only future N=2

openai-pro APPROVE_WITH_COMMENTS at #2181 (sha be9a9c9): canvas
line 127 mixed live N=1 authority with speculative N=2 candidate in one
current-state cost count.

Per P1 Documentation Describes Live State + P2 single-authority metadata:
the live count at HEAD is `cost × 3 targets = 3 per-target instances` (× 4
authoring-multiplier per Option (ii) Con = 12 fns). The `emission_provenance
× 3` figure is a reopen-only future scenario that materializes only if
emission_provenance becomes the second real target-context lens at producer-
wiring landing time.

Updated to separate the two clearly: live count + reopen-only future
scenario marked separately. Aligns with the grep-verified N=1 finding
established earlier in canvas §3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): T-CostLens worker brief — ε supersession header (γ retained as context)

PR #2181 merged at eff426d ratifies ε path canonical-not-transitional
for cost composition. Brief was authored under γ scope (.dag-side
Lookup<SymbolicCost> composition). Add binding ε supersession header at
top; retain γ section as historical context per single-authority
discipline. cost.dag stays PROXY under ε; composition is Rust-side
(abstract SymbolicCost shape × per-primitive realization values).

Authority: Director ratification at #2181 #issuecomment-4401584012.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Complexity-Composition-Layering canvas — DRAFT (factoring tested, ε precedent does NOT apply)

Director authorized canvas authoring at #828 c#4402669133 as
parallel structure to Q-Cost-Composition-Layering (ε RATIFIED). Substrate-
grep on src/v3/lenses/complexity.dag at HEAD shows the factoring claim
DIFFERS from cost-lens:

- Cost-lens needed (target-agnostic shape × target-specific values)
  factoring → Rust-side composition (ε)
- Complexity-lens has NO target-specific axis; output is structural
  property of DAG topology + algebra-instance composition; substrate-
  native fully-on-.dag-side completion

Mgr provisional reading: ε precedent does NOT apply; complexity-lens
BEHAVIORAL COMPLETION is direct slice-tier substrate authoring (carrier
introduction follows SymbolicCost precedent + T-E-P P1 carrier
consumption). Director ratification ask: Q1 (factoring finding correct),
Q2 (slice-tier directly bypassing canvas), Q3 (fresh worker pin).

Cross-Mgr: Verification Mgr (#2075) pinged on v2-oracle snapshot capture
status (cross-cutting prerequisite for #1950/#1951 cementing dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LBP complexity-lens substrate-completion worker brief (Q1/Q2/Q3 RATIFIED)

Pre-authored brief for complexity-lens BEHAVIORAL COMPLETION substrate
work per Director Q1/Q2/Q3 ratification at #828 c#4402714255.

Three deliverables: carrier introduction (ComplexityCost / WorkSpan /
AsymptoticClass following SymbolicCost precedent) + lens widening
(complexity.dag PROXY → COMPLETE) + T-E-P P1 carrier consumption
(DescentEvidence / CallPattern / SubValueRelation for asymptotic
classification of recursive-call behavior).

Indirect-variant dependency surfaced as worker-grep concern at slice-
authoring time (T-E-P P1 Slice 5+ pending; eager-bat-178 stream).

Cementing test (#1950) is separate downstream brief; v2-oracle snapshot
ownership pending Q4 cross-Mgr ratification.

Worker pin: fresh-pool pick at dispatch time (NOT eager-bat-178 per
Director Q3 framing; NOT fierce-ram-21 busy with cost-lens ε).

Same-window-dispatch discipline applies post-canvas-merge (PR #2197).

Pre-authored vs pre-known discipline applied per
feedback_pre_known_vs_pre_authored_briefs.md memorialized 2026-05-08.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): rewrite complexity-lens brief consuming live design authority (codex BLOCKING fix)

Codex BLOCKING (3 findings) at #2199 sha 7a8bb6d:
1. Brief authored against missing canvas instead of reconciling with
   docs/design-complexity-lens-behavioral-completeness.md (which exists
   at HEAD with comprehensive substrate spec)
2. Producer coverage treated as optional corpus scope; should be hard
   T-E-P-Producer-Broadening prerequisite
3. Stale/non-in-repo planning authority cited; should be r3-structure.md
   row 146 (T-LBP slice 1)

All three BLOCKING findings VALID — substrate-grep-before-authoring
discipline failure on my part (feedback_substrate_grep_before_authoring
already memorialized; violated own discipline).

Rewrite delegates carrier shape, dimension wiring, and consumer rewrite
to live design doc §§1.1-1.6 verbatim:
- §1.1 SymbolicCost — already at algebra.dag; no change
- §1.2 SizeVariable — display_name enrichment
- §1.3 work_dimension + span_dimension — two AnalysisDimension instances
- §1.4 AsymptoticClass + BoundedLattice instance
- §1.5 Certainty (cost-aware composition; no lattice)
- §1.6 cost_bound_to_symbolic projection
- §1.7 ComplexitySummary record + lens widening

T-E-P P1 hard prerequisite per design's authority discipline + r3-
structure.md row 146; STOP-and-PING if T-E-P P1 not COMPLETE at slice
authoring time. Authority cites updated to live r3-structure.md row 146.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas — DRAFT (canvas-tier P1 procedure per Q6 RATIFIED)

Director Q6 RATIFIED canvas-tier-required at #828 c#4403163639
for PerfWithinBaseline TestPredicate variant authoring. Three substantive
substrate-shape questions resolved:

Q1 baseline shape: (a) literal-Int rejected as strict-mirror-of-CostBounded
defeats semantic load; (b) DeclarationRef-to-stored-data composes
LensOutputEquals + data X: SymbolicCost precedent at HEAD; (c) runtime-
fixture-injection over-authors. Mgr lean (b).

Q2 ComparisonOp composition: (i) reuse existing ComparisonOp via test-
runner-side resolution matches LensOutputEquals path; (ii) new relative-
op-set introduces parallel-representation debt. Mgr lean (i).

Q3 baseline-storage scope: (α) in-scope slice authors example data; (β)
out-of-scope variant-only slice + PB consumer authors baseline data
matches existing layering. Mgr lean (β).

Combined Mgr lean: Q1(b) + Q2(i) + Q3(β) — variant authored as
compositional extension; baseline-storage is PB consumer-tier work.

Cross-Mgr: PB Mgr #2138 worker (crisp-swift-433) holds dispatch on #2204
land; T-Tier3-Dissolution #2085 R-4 prereq encoded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas REVISED (supersedes wrong-shape original)

Director disposition at #828 c#4403265220 authorized
supersession after BLOCKING at PR #2209 c#4403246233 verified VALID:
original canvas conflated symbolic SymbolicCost (cost-lens substrate)
with wall-clock measured median/p99 baseline (T-Tier3 perf gate
substrate per docs/r3-structure.md:225 + :461 Director-locked 2026-04-28).

Revised canvas frames as two-path ratification:
- P1 author full perf-budget substrate in-R3 (multi-slice; pattern-5
  genuinely-novel substrate-fact-introduction)
- P2 explicitly post-R3 per Director-locked recommendation (zero in-R3
  effort; structural close per r3-structure.md:461 'R3 deliverable is
  structural close; perf is downstream')

Mgr lean: P2 — Director-locked recommendation explicit; trigger-
condition ('someone authors perf-budget claim with concrete numbers
and tooling') not met; R3 horizon constraint argues against multi-
slice perf-budget substrate adding to 5-orthogonal-dependency picture.

Original canvas at q-perf-within-baseline-canvas.md retained with
SUPERSEDED-BY header per durable-decision-record discipline.

5th discipline-failure of 2026-05-08 cycle: substrate-grep verified
substrate-precedent but missed consumer-side requirement at canonical
authority doc; Director self-flagged symmetric two-axis verification
gap; canvas-finding-taxonomy needs precondition 'consumer-side
requirement grep-verified at canonical authority doc'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas-revised — correct trigger-condition framing per Director c#4403297623

Director caught second-axis grep failure on revised canvas: my P2
reasoning #1 ("path-trigger condition for P1 is not met") was
structurally wrong. Existing tooling at HEAD substantially meets the
Director-locked 2026-04-28 trigger-condition ("someone authors the
perf-budget claim with concrete numbers and tooling"):

- docs/briefs/r3-pb-tier3-perf-budget-worker.md
- docs/audit/c1-tier3-perf-budget-readiness-matrix.md
- src/v3/compiler/benches/tier3_mirror_perf.rs
- docs/audit/c1-tier3-baseline-capture-procedure.md
- docs/audit/c1-r3-canonical-bench-host-decision-matrix.md

Plus thresholds (≤2× median, ≤5× p99) + capture discipline (N=3 min,
N=5 preferred) + canonical bench host option matrix.

P1 is bridging existing tooling to substrate (compositional-extension),
NOT multi-slice greenfield genuinely-novel pattern-5 as originally
framed. Smaller scope than canvas-finding-taxonomy pattern 5 implies.

Path-call genuinely depends on PB Mgr's R-3 (canonical CI bench host)
+ R-7 (tier3_baseline.json baseline-capture path) decisions per their
audit response at c#4403059897. Path-call DEFERRED to cross-Mgr
coordination outcome with PB Mgr (#2074); Substrate Mgr surfaces with
corrected framing this turn.

Sixth discipline-failure of cycle (mine, second-axis grep gap on
existing-tooling state); same-class as Director's first-axis grep gap
on consumer-side requirement at the prior turn. Memorialized as
two-axis verification discipline anchor.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-ValueBody-Drift-Resolution canvas — DRAFT (codegen-generation lean)

D1 substrate-shape question per Q-ValueBody-Isomorphism RATIFIED at
#828 c#4403972737. Variant-inventory readiness input from
PR #2218 (merged 2026-05-08) confirms drift: Rust 5 variants vs
substrate 3 constructors; asymmetry on Scalar+List Rust-only +
Map payload-parity-with-semantic-gap.

Two-axis verification at HEAD:
- Substrate-precedent: codegen tooling exists (regen_bootstrap_emit;
  5 _generated.rs files; regen_bootstrap binary). Pattern-3 strict-
  mirror codegen extension applies; no pattern-5 P1 procedure.
- Consumer-side requirement: V1 worker brief explicitly names mirror-
  parity-vs-codegen-generation as D1 path-pair.

Mgr lean: (b) codegen-generation. Path (a) mirror-parity perpetuates
parallel-representation debt; (b) dissolves the dual-taxonomy class
by construction (substrate canonical, Rust codegens). Map dup-key gap
handled via (ii) Rust-side post-codegen wrapping (substrate stays
minimal).

Director ratification ask: D1 (b) + D1-followup (ii).

Carrier slice path post-ratification: extend regen_bootstrap_emit;
add Scalar+List constructors to substrate; regen + remove hand-Rust
enum; handle Map dup-key per ratified followup. Worker pin fresh-pool
per same-window-dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-ValueBody-Drift-Resolution canvas amend authority cite (codex BLOCKING fix)

Director ratified (α) amendment-PR at #828 c#4404398425
post-codex-BLOCKING at PR #2222 c#4404360699.

Canvas originally cited regen_bootstrap_emit.rs as codegen authority
for ValueBody runtime mirror; corrected to scripts/regen_runtime_mirrors.py
which is the substrate→Rust runtime-mirror generator (reads substrate.dag,
emits dag_scalar_generated.rs etc.). regen_bootstrap_emit.rs is a
separate codegen system that generates bootstrap_generated.rs (bootstrap
parser/lower compile snapshot).

D1 (b) codegen-generation ratification UNCHANGED; only authority-path
cites corrected. Carrier slice path at canvas §6-step plan now references
correct runtime-mirror generator. Canvas inline notes mark amendment
location for future-reader audit trail.

8th cycle-tier framing-failure (Mgr-tier; same fine-granularity gap
parallel to Director-tier failure at c#4404256128). Two-axis verification
discipline applied at insufficient granularity (verified codegen-tooling-
exists but didn't disambiguate against bootstrap-vs-runtime-mirror systems).

Discipline anchor refinement: when canvas cites a codegen system /
tooling / authority path, identify the SPECIFIC generator/handler for
the target-file-class. Don't accept 'tooling exists' at coarse granularity.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 8, 2026
… recreated [supersedes #1957] (#2221)

* WIP: Substrate T-CostLens-Composition behavioral completion (γ-ratified) — re

* WIP: Substrate T-CostLens-Composition behavioral completion (γ-ratified) — re

* docs(lenses): cost.dag deferred-discussion — α-revised Slice A0 receipts

Drops unused CallableRealization + DeclarationId imports per codex review
on PR #2171 (imports were scaffolding for the Slice A1 helper which is
HELD pending Director ratification).

Adds T-CostLens-Composition status block citing γ-ratification +
5-option matrix (α-revised / α / β / β-extended / ε / γ-extended) +
4 structural findings forcing the matrix:
  1. No `data cost_lens: Lens<SymbolicCost>` row at HEAD
  2. `Lens<C>.read` carries no target-context (STOP criterion #1)
  3. Behavior→primitive-identity tractable via TransformTarget
  4. No `.dag`-side `List<CallableRealization>` iteration precedent

Per Substrate Mgr disposition at gunbc#2068 #issuecomment-4400747562:
α-revised pure-docs landing while Director ratification at gunbc#828
#issuecomment-4400401643 stays open.

Refs: #2141

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: T-CostLens-Composition α-narrow receipts — gates #38 + #39 closure

Director ratified α (narrow) at gunbc#828 c#4400772335 (relay via
Substrate Mgr at gunbc#2068 c#4401002201). β rejected per
feedback_isomorphism_or_generation_for_mirrors; γ-extended deferred to
its own Q-Lens-Target-Context PROPOSAL canvas.

Same-slice closure receipts:
  - Gate #38 (coercion_cost_equals_complexity_by_construction):
    SATISFIED-BY-CONSTRUCTION at HEAD — Semiring<SymbolicCost> sole
    composition authority at src/v3/std/algebra.dag:181-188
  - Gate #39 (no_coercion_cost_dimension):
    SATISFIED-BY-CONSTRUCTION at HEAD — SymbolicCost 7-variant sole
    cost dimension; no parallel CoercionCost carrier per grep

Deferred gates (#37 / #40 / #70) cite follow-on cross-cutting
Behavior→primitive-identity wiring canvas at #2175.

Updates:
  - docs/r3-program-plan.md §10.3 row: α-narrow disposition + #2175 link
  - docs/r3-program-plan.md gate table rows #37-#40 + #70: status update
  - docs/v3-lens-capability-register.md cost.dag row: α-narrow receipt
  - src/v3/lenses/cost.dag header + deferred-discussion: replace
    5-option matrix with Director-ratified α disposition + 4 findings

Refs: #2141; closes-by-construction §1.8 #38 + #39; defers #37/#40/#70
to #2175.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(receipts): split SymbolicCost type vs composition-fn citations

Per cursor/composer-2 review on PR #2171 sha 0ce7c6f: the
src/v3/std/algebra.dag:181-188 range is the SymbolicCost type + 7
variants only; sequential/iterate composition fns live at lines
262-272. Citation slip fixed in 3 receipt locations to keep
navigable.

#2141 (parent issue) confirmed correct in cost.dag header — exploratory
clarification: PR is #2171, work-item issue is #2141.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Revert "docs(receipts): split SymbolicCost type vs composition-fn citations"

This reverts commit c5ed455.

* Revert "docs: T-CostLens-Composition α-narrow receipts — gates #38 + #39 closure"

This reverts commit 0ce7c6f.

* Revert "Revert "docs: T-CostLens-Composition α-narrow receipts — gates #38 + #39 closure""

This reverts commit 63d9d4f.

* docs(cost.dag): replace stale `~357 below` line pointer with named-section ref

Per codex review on PR #2171 sha 63d9d4f (now stacked on un-revert
commits c120bf1 + d4df2b0 → 63d9d4f): the line-number pointer
"~357 below" referenced a position that shifted after the
deferred-discussion insertion. Replaced with a named-section pointer
("Cost dimension data declaration / forward Lens boundary") that
doesn't decay under future edits.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens worker brief — ε supersession header (γ retained as context)

PR #2181 merged at eff426d ratifies ε path canonical-not-transitional
for cost composition. Brief was authored under γ scope (.dag-side
Lookup<SymbolicCost> composition). Add binding ε supersession header at
top; retain γ section as historical context per single-authority
discipline. cost.dag stays PROXY under ε; composition is Rust-side
(abstract SymbolicCost shape × per-primitive realization values).

Authority: Director ratification at #2181 #issuecomment-4401584012.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cost.dag): refresh status header for ε ratification (#2181)

Aligns in-file header with §10.3 row + capability-register row updates
already on main: BEHAVIORALLY PROXY → BEHAVIORALLY COMPLETE FOR
ABSTRACT-SHAPE per ε ratification at gunbc#2181 c#4401584012. Cost
factors as (target-agnostic abstract SymbolicCost — this file) ×
(target-specific concrete cost — Rust-side consumer per ε); concrete
wiring lives Rust-side, this file's substrate role unchanged.

Slice 0 of T-CostLens follow-on (#2141 ε scope per gunbc#2068
c#4402339074); Slice 1+ (Rust-side composition fn + test_runner
consumer + demo fixture) lands subsequently.

Refs: #2141; aligns with PR #2181 ε ratification.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Substrate T-CostLens-Composition behavioral completion (γ-ratified) — re

* fix(v3): Slice 1a fmt + sg0 ratchet + cost.dag header revert per BLOCKING review

Three fixes on PR #2194 (T-CostLens Slice 1a):

1. **cost.dag header** (BLOCKING per codex review on sha 8ff4ee9):
   reverted "BEHAVIORALLY COMPLETE FOR ABSTRACT-SHAPE" → "BEHAVIORALLY
   PROXY" to align with `docs/v3-lens-capability-register.md` cost.dag
   row (single-authority discipline per INVARIANTS P2). ε ratification
   context retained; status promotion deferred to canvas-tier consumer
   landings.

2. **fmt** (rustfmt diff on sha 6548ccf): collapsed
   `build_for_language` signature to one line; expanded
   `let Some(..) else { continue }` to multiline form per rustfmt
   default.

3. **sg0_census_test** (T-PB-A non-test SG-0 sub-ratchet): added
   `lens_cost_target_composition.rs` to EXPECTED_HAND_AUTHORED_NON_TEST
   with comment citing #2141 ε scope + #2181 ratification. New hand-Rust
   under Director-ratified ε scope authority; mirrors emit/rust_target.rs
   pattern (which is already in the list).

Refs: #2141, #2194, #2181 ratification.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cost.dag): clarify Slice 1a scope vs multi-slice plan per review

Per codex APPROVE_WITH_COMMENTS on PR #2194 sha 6548ccf: the header
phrasing "T-CostLens follow-on slice closes #37 + #40 + #70 via
Rust-side composition fn + test_runner consumer + demo fixture"
overstated this PR's scope — Slice 1a only lands RealizationCostTable
infra, not the consumer/runner/fixture.

Reframed to clarify it's the multi-slice PLAN (sequenced across separate
PRs) that closes the gates, not this single PR. Cites Slice 1a (PR
#2194) as the current commit + Slice 1b/2/3 as forthcoming.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* test(v3): Slice 1a builder smoke test against bootstrap rust.dag

Per Mgr disposition at gunbc#2068 c#4402516739: minimal 1a self-test
at the boundary (TESTING.md discipline — each slice self-testing at its
own boundary rather than relying on downstream slices to validate
upstream behavior). Exhaustive variant coverage lives in Slice 1b's
parameterized-fold tests.

Test asserts:
1. `build_for_language(dag, rust_id)` succeeds against bootstrap dag
2. Resulting table has at least one TypeRealization (non-empty)
3. `type_cost(Int)` returns Some(1) per src/v3/spec/rust.dag `rust_int`
   row (line ~118: `cost: 1`)

A 1a-broken table-builder caught here directly is a much shorter bisect
than waiting for Slice 1b regression.

Refs: #2141, #2194.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(v3): remove pub Default on RealizationCostTable per BLOCKING review

Per gpt-5-5-pro REQUEST_CHANGES on PR #2194 sha 6548ccf (BLOCKING #1
LAYER MODEL): public `Default` derive allowed downstream consumers to
construct an empty/ungrounded cost table without going through
`build_for_language` (substrate-derived facts could be fabricated;
fail-closed-at-substrate-consumer-boundary violated).

Removed `Default` derive; replaced internal `Self::default()` call site
with private `Self::empty()` initializer (module-private, used only by
`build_for_language`). Public construction now goes through the build
fn that requires `(Dag, DeclarationId)` inputs.

BLOCKING #2 (cost.dag status overstating live behavior) was already
addressed in commit 5a89f2f — reviewer was looking at sha 6548ccf
which predates that fix.

Refs: #2141, #2194.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(v3): drop pub *_count() L-8 lens-surface-gate violations

CI v3 job L-8 lens surface gate flagged `pub fn type_count() -> usize`
+ `callable_count` + `operator_count` + `behavior_count` as collapsing
typed carriers to primitives (`pub fn .*-> (usize|bool|i64)` rejected).

These methods existed only as test affordances; the smoke test now
asserts non-emptiness via the `type_cost(Int) == Some(1)` lookup
directly (a successful Some(1) implicitly proves table non-empty +
bootstrap row landed).

cost lookups (`type_cost`/`callable_cost`/`operator_cost`/`behavior_cost`)
return `Option<i64>` which dodges the L-8 regex (the lens-surface gate
matches `-> i64` directly, not `-> Option<i64>`).

Refs: #2141, #2194.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(v3): fail-closed on no-realization-costs language per BLOCKING review

Per gpt-5-5-pro REQUEST_CHANGES on PR #2194 sha 36e63d2 (LAYER MODEL +
Fail-Closed BLOCKING): `build_for_language` previously returned
`Ok(empty table)` when language_id matched zero realization rows —
fabricated-empty-table fail-closed contract violation. Downstream
consumers could see "plausible None lookups" instead of typed build
failure for bogus / unsupported language ids.

Added `BuildError::NoRealizationCostsForLanguage { language: DeclarationId }`
variant; post-loop check returns this error if all 4 maps are empty
(language id is bogus OR spec has no realization rows authored — both
bug-like states).

Negative test `build_for_non_language_id_fails_closed` covers the path:
passing the `Int` primitive's DeclarationId (not a LanguageSpec) yields
`NoRealizationCostsForLanguage` carrying the bogus id back.

Refs: #2141, #2194.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* ci: trigger fresh run for PR-body re-validation (SG-0 pairing line)

* fix(v3): mirror rust_target row-validity contract for parallel-acceptance fix

Per codex REQUEST_CHANGES on PR #2194 sha 9ed08bc (BLOCKING / INVARIANTS
P2 + modeling-discipline practices 5+6 single-authority metadata): my
builder accepted realization rows on weaker criteria than
emit/rust_target.rs:779+ (only checking language/target/op/cost,
ignoring carrier/is_copy/fields/strategy/parameters). Created parallel
acceptance authorities on one substrate boundary.

Added coarse-grained field-presence checks per category mirroring
rust_target's acceptance:
- TypeRealization: + carrier (String) + is_copy (Bool) + fields (present)
- CallableRealization: + strategy (present) + parameters (present)
- OperatorRealization: + carrier (String)
- BehaviorRealization: + carrier (String)

New helpers `require_field_string` / `require_field_bool` mirror the
rust_target patterns; `require_field_present` is a coarse-grained
presence check for fields whose internal shape is validated at
bootstrap-inhabitance time.

Refs: #2141, #2194.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* ci: trigger fresh run with SG-0 pairing class (b) Director-budget citation

* feat(v3): T-CostLens 1a.0 — declaration_by_name substrate accessor + delete rejected hand-Rust

Implements Director-ratified path (α) at gunbc#828 c#4402899692 +
Substrate Mgr re-dispatch at gunbc#2068 c#4402966788: introduce
`declaration_by_name(d: Dag, name: String) -> Declaration?` as `host`
substrate accessor (strict mirror of `declaration_by_id` at
substrate.dag:541-543), enabling `.dag`-tier consumers to acquire
substrate meta-type DeclarationIds at compile time.

Changes:
1. `src/v3/std/substrate.dag` — new `fn declaration_by_name` host fn
   below `declaration_by_id`; comment refresh at line 54 reflecting
   accessor now-landed.
2. `src/v3/spec/rust.dag` — `rust_declaration_by_name_accessor` carrier
   (`({p0}).declaration_by_name(&{p1}).cloned()`) + binding to
   `rust_language`. Mirrors declaration_by_id_binding_rust shape.
3. **Delete** `src/v3/compiler/src/lens_cost_target_composition.rs`
   (the 374-line stage0 hand-Rust addition NACK'd by Director at
   gunbc#828 c#4402795815 for P0 zero-hand-Rust violation).
4. Drop module wiring from lib.rs.
5. Drop file from sg0_census_test.rs EXPECTED_HAND_AUTHORED_NON_TEST
   (returns SG-0 §1.8 #8 ratchet to its prior position; net stage0
   hand-Rust delta = 0 per Director acceptance gate 4).

Sub-slice 1a.1 (consumer at .dag-tier in compiler.dag-or-analog)
follows in subsequent commit on this PR. Re-implementation will use
`declaration_by_name` to acquire `TypeRealization` /
`CallableRealization` etc. meta-type DeclarationIds for filtering
`d.declarations` by `meta_tag`.

Refs: #2141 (T-CostLens-Composition); #2181 ε ratification;
gunbc#828 c#4402899692 (α path ratification); gunbc#2068 c#4402966788
(re-dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore(v3): regen bootstrap_generated.rs after declaration_by_name addition

Operator-side bootstrap regen on PR #2194 1a.0 commit ec9ecd7 per
Substrate Mgr re-fire at gunbc#2068 c#4403961218 (cargo environment
fix broadcast). Propagates `fn declaration_by_name` substrate fn from
src/v3/std/substrate.dag into committed bootstrap snapshots.

Regen command: `cargo run -p v3-compiler --features bootstrap-regen-fresh
--bin regen_bootstrap` (per panic message authority); verify pass:
`regen_bootstrap --verify: committed snapshots match fresh compile.`

next_declaration_id 2453→2457 (matches the 4 new declarations from
substrate.dag fn + rust.dag SubstrateAccessorRealization +
SubstrateAccessorBinding + comment-refresh).

Refs: #2141, #2194; unblocks Operator-Bootstrap-Regen-Cargo-Shim-Wedge
named-token blocker on #2141 body.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Substrate T-CostLens-Composition behavioral completion (γ-ratified) — re

* feat(v3): T-CostLens 1a.1 — declaration_by_name consumer at .dag-tier

ε-ratified Slice 1a.1 (#2141 ε scope per gunbc#2181
ratification): introduces `src/v3/lenses/cost_target_realization.dag`
as the first `.dag`-tier consumer of the `declaration_by_name`
substrate accessor landed in 1a.0 (PR #2194 commit 633f838).
Provides per-category meta-type `Declaration?` resolvers for
`TypeRealization` / `CallableRealization` / `OperatorRealization` /
`BehaviorRealization` — minimum-viable consumer-proof per INVARIANTS
P2 (closes the same-PR-consumer-evidence concern codex BLOCKING
surfaced post-merge on PR #2194).

Wiring:
- `src/v3/lenses/cost_target_realization.dag` — new lens module.
- `src/v3/compiler/regen.dag` — registry entry for the new lens.
- `src/v3/compiler/build.rs` — REGEN_OUTPUTS includes the generated
  projection.
- `src/v3/compiler/src/lib.rs` — exposes the four meta-resolvers.
- `src/v3/compiler/src/lens_cost_target_realization_generated.rs` —
  generated Rust projection (4 fns).
- `src/v3/compiler/src/bootstrap_generated{,_without_parse_surface}.rs`
  — bootstrap regen reflects the new lens-registry entry.

Tests (P2 consumer-proof):
- `tests/integration/lens_cost_target_realization_test.rs` — 4 tests,
  one per meta-type, asserting `declaration_by_name` resolves the
  `Declaration` whose `name` equals the requested string.
- `sg0_census_test.rs` EXPECTED_HAND_AUTHORED_TEST entry.

Out of scope (later sub-slices): full realization-row walking via
`d.declarations` fold + `meta_tag` filter + `ValueBody.Structural.fields`
extraction (Slice 1a.2); composition of abstract `SymbolicCost` shape
× per-target realization-cost (Slice 1a.3+); demonstration fixture #70
(Slice 3); test_runner #40 wiring (Slice 2 PINGs Verification Mgr).

Refs: #2141 work-item; #2181 ε ratification; gunbc#828 c#4402899692
(α path ratification); gunbc#2068 c#4402999167 (split-PR sequencing).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(v3): Slice 1a.1 same-PR ratchet updates per CI failures

Four ratchets needed updating after Slice 1a.1 (cost_target_realization
lens registry entry) on PR #2221:

1. fmt: integration.rs sorting (rustfmt re-alphabetizes the new
   lens_cost_target_realization_test entry).
2. m1_substrate_test::substrate_accessor_rust_binding_invariants:
   expected count 6→7 reflecting the new declaration_by_name accessor
   from Slice 1a.0 (now visible to this PR's test scope).
3. docs/v3-lens-capability-register.md: capability-register row for
   `cost_target_realization.dag` per discipline rule #1
   (every regen.dag LensRegistryEntry needs a register row); status
   TERMINAL/N/A — ε path consumer-evidence-only, not a v2 mirror.
4. sg6_hand_authored_census_test: registry-triple snapshot includes
   the new (name, lens_file, generated_file) tuple.
5. parse_corpus_manifest.txt: refreshed item-counts/byte-counts/fnv
   for the 3 .dag files that gained content (regen.dag,
   spec/rust.dag, std/substrate.dag).

All 4 previously-failing tests now pass locally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(v3): Slice 1a.1 — add TypeInstantiationRealization + PatternRealization meta accessors

Per codex BLOCKING on PR #2221 sha 3ea2573: meta-type roster was
hand-enumerated to 4 categories (Type/Callable/Operator/Behavior)
instead of mirroring the std.emit_model realization ontology which has
6 cost-bearing carriers. Adds the two missing accessors:

- `type_instantiation_realization_meta(d) -> Declaration?`
- `pattern_realization_meta(d) -> Declaration?`

Plus 2 new P2 consumer-proof tests, bringing the test suite to 6/6
covering all `*Realization` meta-types declared at
`src/v3/std/emit_model.dag` (TypeRealization, CallableRealization,
OperatorRealization, BehaviorRealization, TypeInstantiationRealization,
PatternRealization).

Other 2 BLOCKINGs from the same review:
- Capability-register row missing: already addressed at commit
  9ef7402 (reviewer was looking at older sha 3ea2573).
- Hand-Rust test rather than .dag TestClaim: discipline-tier resolved
  by Mgr standing-authority approval at gunbc#2221 c#4404395097-range
  accepting the hand-Rust test under EXPECTED_HAND_AUTHORED_TEST as
  P2 evidence.

Refs: #2141, #2221.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(sg0): cite P5 dissolution trigger for Slice 1a.1 hand-Rust test

Per codex BLOCKING on PR #2221 sha 3ea2573 at sg0_census_test.rs:386:
the EXPECTED_HAND_AUTHORED_TEST entry for
`lens_cost_target_realization_test.rs` documented scope but not the
dissolution trigger, leaving the new hand-Rust test as untracked P5
debt under the hand-Rust gate.

Updated the entry's comment to cite:
1. The natural dissolution trigger: T-Tests-As-Data infrastructure
   expressing ".dag-fn-resolution-against-bootstrap" assertions as
   structural TestClaim data (per #1966 §3 ratchet predicate scope).
2. The 6 assertions' factoring shape (OutputEquals /
   declaration-resolution claims under T-Tests-As-Data umbrella).
3. The Mgr standing-authority bridge ratification at gunbc#2221
   #issuecomment-4404395097.

Refs: #2141, #2221.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(v3): drop .as_str() from declaration_by_name carrier — clippy needless-borrow

CI v3 clippy on PR #2221 sha 59d0853 flagged `&&String` from carrier
`&{p1}.as_str()` shape. Simplified carrier to `({p0}).declaration_by_name({p1}).cloned()`;
emit pipeline auto-adds `&`, yielding clean `&String` (auto-derefs to
`&str` matching `Dag::declaration_by_name(&str)` signature).

cargo clippy --all-targets clean.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(v3): reorder lib.rs modules so rustdoc attaches correctly

Per gpt-5-5-pro APPROVE_WITH_COMMENTS on PR #2221 sha 59d0853:
my insertion of `pub mod lens_cost_target_realization` placed it
between an existing rustdoc and `pub mod lens_cost_symbolic`,
silently re-attaching the rustdoc (about `Behavior`/`LoopBound`
substrate-ownership pattern) to the wrong module.

Reordered so:
1. `lens_cost_symbolic` follows its original rustdoc.
2. `lens_cost_target_realization` follows below with its own
   accurate rustdoc citing Slice 1a.1 + ε scope + the 6 per-category
   meta-type resolvers.

Net diff: identical fn surface; just rustdoc-attachment correctness.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(v3): refresh parse manifest after rust.dag carrier-byte shift

Carrier change in commit 2f78154 (`{p1}.as_str()` → `{p1}`) shifted
rust.dag by 1 byte (1357477→1357476) + fnv hash. Manifest needs same-PR
update per parse-snapshot ratchet.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 8, 2026
…ist completeness (post-#2221 followup) (#2229)

* WIP: Substrate T-CostLens-Composition behavioral completion (γ-ratified) — re

* WIP: Substrate T-CostLens-Composition behavioral completion (γ-ratified) — re

* docs(lenses): cost.dag deferred-discussion — α-revised Slice A0 receipts

Drops unused CallableRealization + DeclarationId imports per codex review
on PR #2171 (imports were scaffolding for the Slice A1 helper which is
HELD pending Director ratification).

Adds T-CostLens-Composition status block citing γ-ratification +
5-option matrix (α-revised / α / β / β-extended / ε / γ-extended) +
4 structural findings forcing the matrix:
  1. No `data cost_lens: Lens<SymbolicCost>` row at HEAD
  2. `Lens<C>.read` carries no target-context (STOP criterion #1)
  3. Behavior→primitive-identity tractable via TransformTarget
  4. No `.dag`-side `List<CallableRealization>` iteration precedent

Per Substrate Mgr disposition at gunbc#2068 #issuecomment-4400747562:
α-revised pure-docs landing while Director ratification at gunbc#828
#issuecomment-4400401643 stays open.

Refs: #2141

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: T-CostLens-Composition α-narrow receipts — gates #38 + #39 closure

Director ratified α (narrow) at gunbc#828 c#4400772335 (relay via
Substrate Mgr at gunbc#2068 c#4401002201). β rejected per
feedback_isomorphism_or_generation_for_mirrors; γ-extended deferred to
its own Q-Lens-Target-Context PROPOSAL canvas.

Same-slice closure receipts:
  - Gate #38 (coercion_cost_equals_complexity_by_construction):
    SATISFIED-BY-CONSTRUCTION at HEAD — Semiring<SymbolicCost> sole
    composition authority at src/v3/std/algebra.dag:181-188
  - Gate #39 (no_coercion_cost_dimension):
    SATISFIED-BY-CONSTRUCTION at HEAD — SymbolicCost 7-variant sole
    cost dimension; no parallel CoercionCost carrier per grep

Deferred gates (#37 / #40 / #70) cite follow-on cross-cutting
Behavior→primitive-identity wiring canvas at #2175.

Updates:
  - docs/r3-program-plan.md §10.3 row: α-narrow disposition + #2175 link
  - docs/r3-program-plan.md gate table rows #37-#40 + #70: status update
  - docs/v3-lens-capability-register.md cost.dag row: α-narrow receipt
  - src/v3/lenses/cost.dag header + deferred-discussion: replace
    5-option matrix with Director-ratified α disposition + 4 findings

Refs: #2141; closes-by-construction §1.8 #38 + #39; defers #37/#40/#70
to #2175.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(receipts): split SymbolicCost type vs composition-fn citations

Per cursor/composer-2 review on PR #2171 sha 0ce7c6f: the
src/v3/std/algebra.dag:181-188 range is the SymbolicCost type + 7
variants only; sequential/iterate composition fns live at lines
262-272. Citation slip fixed in 3 receipt locations to keep
navigable.

#2141 (parent issue) confirmed correct in cost.dag header — exploratory
clarification: PR is #2171, work-item issue is #2141.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Revert "docs(receipts): split SymbolicCost type vs composition-fn citations"

This reverts commit c5ed455.

* Revert "docs: T-CostLens-Composition α-narrow receipts — gates #38 + #39 closure"

This reverts commit 0ce7c6f.

* Revert "Revert "docs: T-CostLens-Composition α-narrow receipts — gates #38 + #39 closure""

This reverts commit 63d9d4f.

* docs(cost.dag): replace stale `~357 below` line pointer with named-section ref

Per codex review on PR #2171 sha 63d9d4f (now stacked on un-revert
commits c120bf1 + d4df2b0 → 63d9d4f): the line-number pointer
"~357 below" referenced a position that shifted after the
deferred-discussion insertion. Replaced with a named-section pointer
("Cost dimension data declaration / forward Lens boundary") that
doesn't decay under future edits.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens worker brief — ε supersession header (γ retained as context)

PR #2181 merged at eff426d ratifies ε path canonical-not-transitional
for cost composition. Brief was authored under γ scope (.dag-side
Lookup<SymbolicCost> composition). Add binding ε supersession header at
top; retain γ section as historical context per single-authority
discipline. cost.dag stays PROXY under ε; composition is Rust-side
(abstract SymbolicCost shape × per-primitive realization values).

Authority: Director ratification at #2181 #issuecomment-4401584012.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cost.dag): refresh status header for ε ratification (#2181)

Aligns in-file header with §10.3 row + capability-register row updates
already on main: BEHAVIORALLY PROXY → BEHAVIORALLY COMPLETE FOR
ABSTRACT-SHAPE per ε ratification at gunbc#2181 c#4401584012. Cost
factors as (target-agnostic abstract SymbolicCost — this file) ×
(target-specific concrete cost — Rust-side consumer per ε); concrete
wiring lives Rust-side, this file's substrate role unchanged.

Slice 0 of T-CostLens follow-on (#2141 ε scope per gunbc#2068
c#4402339074); Slice 1+ (Rust-side composition fn + test_runner
consumer + demo fixture) lands subsequently.

Refs: #2141; aligns with PR #2181 ε ratification.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Substrate T-CostLens-Composition behavioral completion (γ-ratified) — re

* fix(v3): Slice 1a fmt + sg0 ratchet + cost.dag header revert per BLOCKING review

Three fixes on PR #2194 (T-CostLens Slice 1a):

1. **cost.dag header** (BLOCKING per codex review on sha 8ff4ee9):
   reverted "BEHAVIORALLY COMPLETE FOR ABSTRACT-SHAPE" → "BEHAVIORALLY
   PROXY" to align with `docs/v3-lens-capability-register.md` cost.dag
   row (single-authority discipline per INVARIANTS P2). ε ratification
   context retained; status promotion deferred to canvas-tier consumer
   landings.

2. **fmt** (rustfmt diff on sha 6548ccf): collapsed
   `build_for_language` signature to one line; expanded
   `let Some(..) else { continue }` to multiline form per rustfmt
   default.

3. **sg0_census_test** (T-PB-A non-test SG-0 sub-ratchet): added
   `lens_cost_target_composition.rs` to EXPECTED_HAND_AUTHORED_NON_TEST
   with comment citing #2141 ε scope + #2181 ratification. New hand-Rust
   under Director-ratified ε scope authority; mirrors emit/rust_target.rs
   pattern (which is already in the list).

Refs: #2141, #2194, #2181 ratification.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cost.dag): clarify Slice 1a scope vs multi-slice plan per review

Per codex APPROVE_WITH_COMMENTS on PR #2194 sha 6548ccf: the header
phrasing "T-CostLens follow-on slice closes #37 + #40 + #70 via
Rust-side composition fn + test_runner consumer + demo fixture"
overstated this PR's scope — Slice 1a only lands RealizationCostTable
infra, not the consumer/runner/fixture.

Reframed to clarify it's the multi-slice PLAN (sequenced across separate
PRs) that closes the gates, not this single PR. Cites Slice 1a (PR
#2194) as the current commit + Slice 1b/2/3 as forthcoming.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* test(v3): Slice 1a builder smoke test against bootstrap rust.dag

Per Mgr disposition at gunbc#2068 c#4402516739: minimal 1a self-test
at the boundary (TESTING.md discipline — each slice self-testing at its
own boundary rather than relying on downstream slices to validate
upstream behavior). Exhaustive variant coverage lives in Slice 1b's
parameterized-fold tests.

Test asserts:
1. `build_for_language(dag, rust_id)` succeeds against bootstrap dag
2. Resulting table has at least one TypeRealization (non-empty)
3. `type_cost(Int)` returns Some(1) per src/v3/spec/rust.dag `rust_int`
   row (line ~118: `cost: 1`)

A 1a-broken table-builder caught here directly is a much shorter bisect
than waiting for Slice 1b regression.

Refs: #2141, #2194.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(v3): remove pub Default on RealizationCostTable per BLOCKING review

Per gpt-5-5-pro REQUEST_CHANGES on PR #2194 sha 6548ccf (BLOCKING #1
LAYER MODEL): public `Default` derive allowed downstream consumers to
construct an empty/ungrounded cost table without going through
`build_for_language` (substrate-derived facts could be fabricated;
fail-closed-at-substrate-consumer-boundary violated).

Removed `Default` derive; replaced internal `Self::default()` call site
with private `Self::empty()` initializer (module-private, used only by
`build_for_language`). Public construction now goes through the build
fn that requires `(Dag, DeclarationId)` inputs.

BLOCKING #2 (cost.dag status overstating live behavior) was already
addressed in commit 5a89f2f — reviewer was looking at sha 6548ccf
which predates that fix.

Refs: #2141, #2194.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(v3): drop pub *_count() L-8 lens-surface-gate violations

CI v3 job L-8 lens surface gate flagged `pub fn type_count() -> usize`
+ `callable_count` + `operator_count` + `behavior_count` as collapsing
typed carriers to primitives (`pub fn .*-> (usize|bool|i64)` rejected).

These methods existed only as test affordances; the smoke test now
asserts non-emptiness via the `type_cost(Int) == Some(1)` lookup
directly (a successful Some(1) implicitly proves table non-empty +
bootstrap row landed).

cost lookups (`type_cost`/`callable_cost`/`operator_cost`/`behavior_cost`)
return `Option<i64>` which dodges the L-8 regex (the lens-surface gate
matches `-> i64` directly, not `-> Option<i64>`).

Refs: #2141, #2194.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(v3): fail-closed on no-realization-costs language per BLOCKING review

Per gpt-5-5-pro REQUEST_CHANGES on PR #2194 sha 36e63d2 (LAYER MODEL +
Fail-Closed BLOCKING): `build_for_language` previously returned
`Ok(empty table)` when language_id matched zero realization rows —
fabricated-empty-table fail-closed contract violation. Downstream
consumers could see "plausible None lookups" instead of typed build
failure for bogus / unsupported language ids.

Added `BuildError::NoRealizationCostsForLanguage { language: DeclarationId }`
variant; post-loop check returns this error if all 4 maps are empty
(language id is bogus OR spec has no realization rows authored — both
bug-like states).

Negative test `build_for_non_language_id_fails_closed` covers the path:
passing the `Int` primitive's DeclarationId (not a LanguageSpec) yields
`NoRealizationCostsForLanguage` carrying the bogus id back.

Refs: #2141, #2194.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* ci: trigger fresh run for PR-body re-validation (SG-0 pairing line)

* fix(v3): mirror rust_target row-validity contract for parallel-acceptance fix

Per codex REQUEST_CHANGES on PR #2194 sha 9ed08bc (BLOCKING / INVARIANTS
P2 + modeling-discipline practices 5+6 single-authority metadata): my
builder accepted realization rows on weaker criteria than
emit/rust_target.rs:779+ (only checking language/target/op/cost,
ignoring carrier/is_copy/fields/strategy/parameters). Created parallel
acceptance authorities on one substrate boundary.

Added coarse-grained field-presence checks per category mirroring
rust_target's acceptance:
- TypeRealization: + carrier (String) + is_copy (Bool) + fields (present)
- CallableRealization: + strategy (present) + parameters (present)
- OperatorRealization: + carrier (String)
- BehaviorRealization: + carrier (String)

New helpers `require_field_string` / `require_field_bool` mirror the
rust_target patterns; `require_field_present` is a coarse-grained
presence check for fields whose internal shape is validated at
bootstrap-inhabitance time.

Refs: #2141, #2194.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* ci: trigger fresh run with SG-0 pairing class (b) Director-budget citation

* feat(v3): T-CostLens 1a.0 — declaration_by_name substrate accessor + delete rejected hand-Rust

Implements Director-ratified path (α) at gunbc#828 c#4402899692 +
Substrate Mgr re-dispatch at gunbc#2068 c#4402966788: introduce
`declaration_by_name(d: Dag, name: String) -> Declaration?` as `host`
substrate accessor (strict mirror of `declaration_by_id` at
substrate.dag:541-543), enabling `.dag`-tier consumers to acquire
substrate meta-type DeclarationIds at compile time.

Changes:
1. `src/v3/std/substrate.dag` — new `fn declaration_by_name` host fn
   below `declaration_by_id`; comment refresh at line 54 reflecting
   accessor now-landed.
2. `src/v3/spec/rust.dag` — `rust_declaration_by_name_accessor` carrier
   (`({p0}).declaration_by_name(&{p1}).cloned()`) + binding to
   `rust_language`. Mirrors declaration_by_id_binding_rust shape.
3. **Delete** `src/v3/compiler/src/lens_cost_target_composition.rs`
   (the 374-line stage0 hand-Rust addition NACK'd by Director at
   gunbc#828 c#4402795815 for P0 zero-hand-Rust violation).
4. Drop module wiring from lib.rs.
5. Drop file from sg0_census_test.rs EXPECTED_HAND_AUTHORED_NON_TEST
   (returns SG-0 §1.8 #8 ratchet to its prior position; net stage0
   hand-Rust delta = 0 per Director acceptance gate 4).

Sub-slice 1a.1 (consumer at .dag-tier in compiler.dag-or-analog)
follows in subsequent commit on this PR. Re-implementation will use
`declaration_by_name` to acquire `TypeRealization` /
`CallableRealization` etc. meta-type DeclarationIds for filtering
`d.declarations` by `meta_tag`.

Refs: #2141 (T-CostLens-Composition); #2181 ε ratification;
gunbc#828 c#4402899692 (α path ratification); gunbc#2068 c#4402966788
(re-dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore(v3): regen bootstrap_generated.rs after declaration_by_name addition

Operator-side bootstrap regen on PR #2194 1a.0 commit ec9ecd7 per
Substrate Mgr re-fire at gunbc#2068 c#4403961218 (cargo environment
fix broadcast). Propagates `fn declaration_by_name` substrate fn from
src/v3/std/substrate.dag into committed bootstrap snapshots.

Regen command: `cargo run -p v3-compiler --features bootstrap-regen-fresh
--bin regen_bootstrap` (per panic message authority); verify pass:
`regen_bootstrap --verify: committed snapshots match fresh compile.`

next_declaration_id 2453→2457 (matches the 4 new declarations from
substrate.dag fn + rust.dag SubstrateAccessorRealization +
SubstrateAccessorBinding + comment-refresh).

Refs: #2141, #2194; unblocks Operator-Bootstrap-Regen-Cargo-Shim-Wedge
named-token blocker on #2141 body.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Substrate T-CostLens-Composition behavioral completion (γ-ratified) — re

* feat(v3): T-CostLens 1a.1 — declaration_by_name consumer at .dag-tier

ε-ratified Slice 1a.1 (#2141 ε scope per gunbc#2181
ratification): introduces `src/v3/lenses/cost_target_realization.dag`
as the first `.dag`-tier consumer of the `declaration_by_name`
substrate accessor landed in 1a.0 (PR #2194 commit 633f838).
Provides per-category meta-type `Declaration?` resolvers for
`TypeRealization` / `CallableRealization` / `OperatorRealization` /
`BehaviorRealization` — minimum-viable consumer-proof per INVARIANTS
P2 (closes the same-PR-consumer-evidence concern codex BLOCKING
surfaced post-merge on PR #2194).

Wiring:
- `src/v3/lenses/cost_target_realization.dag` — new lens module.
- `src/v3/compiler/regen.dag` — registry entry for the new lens.
- `src/v3/compiler/build.rs` — REGEN_OUTPUTS includes the generated
  projection.
- `src/v3/compiler/src/lib.rs` — exposes the four meta-resolvers.
- `src/v3/compiler/src/lens_cost_target_realization_generated.rs` —
  generated Rust projection (4 fns).
- `src/v3/compiler/src/bootstrap_generated{,_without_parse_surface}.rs`
  — bootstrap regen reflects the new lens-registry entry.

Tests (P2 consumer-proof):
- `tests/integration/lens_cost_target_realization_test.rs` — 4 tests,
  one per meta-type, asserting `declaration_by_name` resolves the
  `Declaration` whose `name` equals the requested string.
- `sg0_census_test.rs` EXPECTED_HAND_AUTHORED_TEST entry.

Out of scope (later sub-slices): full realization-row walking via
`d.declarations` fold + `meta_tag` filter + `ValueBody.Structural.fields`
extraction (Slice 1a.2); composition of abstract `SymbolicCost` shape
× per-target realization-cost (Slice 1a.3+); demonstration fixture #70
(Slice 3); test_runner #40 wiring (Slice 2 PINGs Verification Mgr).

Refs: #2141 work-item; #2181 ε ratification; gunbc#828 c#4402899692
(α path ratification); gunbc#2068 c#4402999167 (split-PR sequencing).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(v3): Slice 1a.1 same-PR ratchet updates per CI failures

Four ratchets needed updating after Slice 1a.1 (cost_target_realization
lens registry entry) on PR #2221:

1. fmt: integration.rs sorting (rustfmt re-alphabetizes the new
   lens_cost_target_realization_test entry).
2. m1_substrate_test::substrate_accessor_rust_binding_invariants:
   expected count 6→7 reflecting the new declaration_by_name accessor
   from Slice 1a.0 (now visible to this PR's test scope).
3. docs/v3-lens-capability-register.md: capability-register row for
   `cost_target_realization.dag` per discipline rule #1
   (every regen.dag LensRegistryEntry needs a register row); status
   TERMINAL/N/A — ε path consumer-evidence-only, not a v2 mirror.
4. sg6_hand_authored_census_test: registry-triple snapshot includes
   the new (name, lens_file, generated_file) tuple.
5. parse_corpus_manifest.txt: refreshed item-counts/byte-counts/fnv
   for the 3 .dag files that gained content (regen.dag,
   spec/rust.dag, std/substrate.dag).

All 4 previously-failing tests now pass locally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(v3): Slice 1a.1 — add TypeInstantiationRealization + PatternRealization meta accessors

Per codex BLOCKING on PR #2221 sha 3ea2573: meta-type roster was
hand-enumerated to 4 categories (Type/Callable/Operator/Behavior)
instead of mirroring the std.emit_model realization ontology which has
6 cost-bearing carriers. Adds the two missing accessors:

- `type_instantiation_realization_meta(d) -> Declaration?`
- `pattern_realization_meta(d) -> Declaration?`

Plus 2 new P2 consumer-proof tests, bringing the test suite to 6/6
covering all `*Realization` meta-types declared at
`src/v3/std/emit_model.dag` (TypeRealization, CallableRealization,
OperatorRealization, BehaviorRealization, TypeInstantiationRealization,
PatternRealization).

Other 2 BLOCKINGs from the same review:
- Capability-register row missing: already addressed at commit
  9ef7402 (reviewer was looking at older sha 3ea2573).
- Hand-Rust test rather than .dag TestClaim: discipline-tier resolved
  by Mgr standing-authority approval at gunbc#2221 c#4404395097-range
  accepting the hand-Rust test under EXPECTED_HAND_AUTHORED_TEST as
  P2 evidence.

Refs: #2141, #2221.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(sg0): cite P5 dissolution trigger for Slice 1a.1 hand-Rust test

Per codex BLOCKING on PR #2221 sha 3ea2573 at sg0_census_test.rs:386:
the EXPECTED_HAND_AUTHORED_TEST entry for
`lens_cost_target_realization_test.rs` documented scope but not the
dissolution trigger, leaving the new hand-Rust test as untracked P5
debt under the hand-Rust gate.

Updated the entry's comment to cite:
1. The natural dissolution trigger: T-Tests-As-Data infrastructure
   expressing ".dag-fn-resolution-against-bootstrap" assertions as
   structural TestClaim data (per #1966 §3 ratchet predicate scope).
2. The 6 assertions' factoring shape (OutputEquals /
   declaration-resolution claims under T-Tests-As-Data umbrella).
3. The Mgr standing-authority bridge ratification at gunbc#2221
   #issuecomment-4404395097.

Refs: #2141, #2221.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(v3): drop .as_str() from declaration_by_name carrier — clippy needless-borrow

CI v3 clippy on PR #2221 sha 59d0853 flagged `&&String` from carrier
`&{p1}.as_str()` shape. Simplified carrier to `({p0}).declaration_by_name({p1}).cloned()`;
emit pipeline auto-adds `&`, yielding clean `&String` (auto-derefs to
`&str` matching `Dag::declaration_by_name(&str)` signature).

cargo clippy --all-targets clean.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(v3): reorder lib.rs modules so rustdoc attaches correctly

Per gpt-5-5-pro APPROVE_WITH_COMMENTS on PR #2221 sha 59d0853:
my insertion of `pub mod lens_cost_target_realization` placed it
between an existing rustdoc and `pub mod lens_cost_symbolic`,
silently re-attaching the rustdoc (about `Behavior`/`LoopBound`
substrate-ownership pattern) to the wrong module.

Reordered so:
1. `lens_cost_symbolic` follows its original rustdoc.
2. `lens_cost_target_realization` follows below with its own
   accurate rustdoc citing Slice 1a.1 + ε scope + the 6 per-category
   meta-type resolvers.

Net diff: identical fn surface; just rustdoc-attachment correctness.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(v3): refresh parse manifest after rust.dag carrier-byte shift

Carrier change in commit 2f78154 (`{p1}.as_str()` → `{p1}`) shifted
rust.dag by 1 byte (1357477→1357476) + fnv hash. Manifest needs same-PR
update per parse-snapshot ratchet.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: cost_target_realization status header + register row resolver-list completeness

Two findings on PR #2221 sha c89b8c0 from codex BLOCKING + inline:

1. **BLOCKING — file-header `Status:` line missing**: per v3 lens
   capability-register discipline, every shipped lens needs an in-file
   `Status: STRUCTURALLY ...; BEHAVIORALLY ...` header line. Added at
   cost_target_realization.dag:6 with TERMINAL/N/A status (matches
   register row) + rationale citing v3-native ε-path consumer-evidence-only
   scope, fail-closed substrate-Option boundary, and register cross-link.

2. **non-blocking — register row only named 4 of 6 resolvers**: updated
   `docs/v3-lens-capability-register.md:42` to list all 6 per-category
   meta-type resolvers added in commit 3ee8419 (TypeRealization +
   CallableRealization + OperatorRealization + BehaviorRealization +
   TypeInstantiationRealization + PatternRealization).

Refs: #2141, #2221.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 9, 2026
…population drift (#2333)

* docs(briefs): Substrate bridge SourceSpan.file participation retirement worker brief

Authored for gunbc#1958 Substrate-owned bridge slice. Targets audit-row #2
(kernel Bool patch BOOL_TYPES_FILE) + row #6 (pipeline authority
PIPELINE_AUTHORITY_FILE) per r3-program-plan.md §5 line 353 scope-narrowing.
Sibling #1959 closed as already-retired by PR #1272.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 Variant-aware projection carrier canvas (#1947)

Surfaces 3 carrier-shape options (α RestResponseProjection variant-tag /
β Declaration variant_projection_metadata / γ free-standing CoproductProjection)
for Director ratification before worker brief authoring. Mgr-tier recommendation
= γ (DeclarationRef-keyed, avoids tag-string-as-identity bridge).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — same-slice prerequisite + section anchor

Director calibration (gunbc#2079 #issuecomment-...):
1. Promote ratchet-test cross-Mgr handoff from conditional Acceptance #4
   to upfront same-slice BLOCKING prerequisite gate (per
   feedback_same_slice_dissolution_discipline).
2. Replace `r3-program-plan.md:353` line-cite with `§5 Y4 scope-clarification`
   section anchor (per feedback_section_anchors_over_line_numbers).

Code-line anchors in bootstrap.rs left as-is (anchor sites worker navigates to).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledger discipline

Address BLOCKING inline review at line 46: bridge_source_span_file_participation_retired
is an Open umbrella whose green predicate is "no production code path consults
SourceSpan.file" per r3-structure.md:115. Partial retirement was explicitly
rejected 2026-04-29 (Director acceptance #1130 / dispatch #1139).

Changes:
- Add Ledger-discipline preamble: umbrella row stays Open; receipt updates
  audit-packet enumeration, NOT bridge_ledger.dag.
- Acceptance #3 reframed: do NOT mutate bridge_ledger.dag; mark rows #2 + #6
  retired in the audit packet only.
- Authority anchor updated: status=Open (not Proposed); add r3-structure.md:115
  + bridge_ledger.dag:125-129 line refs.
- Cross-Mgr section reframed: umbrella ratchet cannot flip on this PR alone;
  Verification's ledger-zero audit progress field is post-merge tracking,
  not a same-slice pre-merge blocker. Reconciles with BLOCKING finding
  (Director calibration #1 assumed umbrella ratchet could flip on partial
  retirement, which r3-structure.md:115 forbids).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)

Director ratification of option γ at gunbc#828 #issuecomment-4394369848.
Free-standing CoproductProjection carrier in src/v3/std/, DeclarationRef-keyed,
typed WireTagValue leaf, 4 same-slice acceptance gates.

Surfaces 3 substrate observations for STOP-and-PING (DeclarationRef String
alias; FieldRef does-not-exist-at-HEAD; tag_field String asymmetry) — worker
must escalate, not silently work around. PB Mgr cross-Mgr ping at carrier
landing (heads-up, not blocker).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-Mgr contradiction

openai-pro REQUEST_CHANGES at PR #2079 #issuecomment-... flagged Acceptance #4
("ratchet test passes ... confirmed-present at HEAD before merge") contradicting
the reframed Cross-Mgr section ("No same-slice ratchet-test gate applies; post-merge
tracking only"). Both said different things about whether the umbrella ratchet
is a pre-merge blocker.

Resolution: Acceptance #4 reframed to explicitly state "No umbrella-ratchet
pre-merge gate" — worker does NOT wait for Verification ratchet authoring;
acceptance for this slice is the audit-packet receipt update in #3. Cross-Mgr
handoff also updated to remove "ratchet authoring" from Verification's same-slice
duties.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP-and-PING items

Director pre-ratified dispositions at gunbc#828 #issuecomment-4394416049:
1. DeclarationRef alias: accept (b) + debt note (re-escalate only on same-slice break)
2. FieldRef: grep-decide between InputFieldRef-as-specialization vs rename
3. tag_field String asymmetry: typed introduction + debt note for migration

Worker proceeds without re-pinging unless evidence forces escalation. STOP-criteria
section narrowed accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)

Director ratification at gunbc#828 #issuecomment-4394427814 + proposal merge
at PR #2096 (commit fec869202): src/v3/std/substrate.dag::Dag IS the reflected
program; no new substrate carrier required. ReflectedProgram<T> rejected.

Gate A patches:
1. r3-program-plan.md §10.3: new Q-Reification row marked RATIFIED with PR #2096
   merge link + Gate A receipt scope (this PR + #1960 closed-as-non-addition).
2. r3-v-pattern-a-tc1-v1-worker.md: 3 sites — status header (Q-Reification
   CLEARED, Branch B η non-vacuity remains), worker-pin gate, E6-G1.a/E3
   producer dependency. Replaces ReflectedProgram<T> with consumer-wiring
   nuance: lens fold consumes Dag via .dag body authority through Evaluator.
3. r3-pr-e6-g1a-option3-static-lens-worker.md: 2 sites — same nuance: deferred
   work is consumer-wiring, NOT a separate carrier.
4. r3-pr-e8-w1-producer-contract-test-plan-worker.md: 1 site — fold-over-Dag
   reframe.

Receipt of pass-by-construction: this PR adds NO new .dag declaration to
src/v3/std/. The ratification is structurally a non-addition (Option A
correctness proof per same-slice dissolution discipline).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — delete superseded canvas + name dissolution trigger for tag_field asymmetry

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings (P2 single-authority
+ P5 dissolution trigger).

Fixes:
1. Delete docs/briefs/r3-substrate-s5-variant-aware-projection-carrier-canvas.md
   (superseded by the γ-ratified worker brief in same PR; would otherwise leave
   two current-looking S5 status authorities post-merge — one saying ratification
   pending, one saying γ ratified).
2. Substrate observation #3 (tag_field String/FieldRef asymmetry) now carries a
   binding named dissolution trigger: when FieldRef exists as top-level carrier
   AND InputFieldRef is classified, migrate InternallyTaggedObject.tag_field via
   follow-on Substrate hygiene PR. Worker MUST add debt-paydown row to authoritative
   debt ledger before merging carrier-introduction PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)

cursor review at gunbc#2079 #issuecomment-... flagged C-1 as mis-keyed:
INVARIANTS.md C-1 is "missing args fail closed; no LitNull sentinels" (P3
fail-closed family), not parallel-representation/duplicate-authority. The
correct cite for rejecting a parallel ReflectedProgram<T> alongside Dag is
P2 single authority (INVARIANTS.md line 148: cost of change is proportional
to how many files encode the same fact).

Cite updated to "INVARIANTS.md P2 single authority" with inline gloss.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — name dissolution trigger for DeclarationRef alias debt

openai-pro REQUEST_CHANGES at gunbc#2079: substrate observation #1 had desired
endpoint ("future structural promotion of DeclarationRef") but no checkable
dissolution trigger — same P5 gap that #3 (tag_field asymmetry) had been fixed
for in commit 2601d7d26.

Trigger now binding: promote DeclarationRef when EITHER
  (a) audit-row #14 (declaration_name_preference_rank / declaration_by_name
      rank-table) closes — dsl/std ↔ src/v3/std module convergence makes
      name-keyed identity unambiguous and structural module identity available,
  OR
  (b) any DeclarationRef-typed consumer surfaces a string-identity bridge per
      feedback_opaque_strings_attract_heuristics (heuristic patching, naming-
      convention dispatch, suffix/prefix matching).

Worker MUST add debt-paydown row before merging carrier-introduction PR (same
pattern as the tag_field debt requirement).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q-PAFS row

codex BLOCKING at gunbc#2079: docs/briefs/r3-pr-e6-g1a-option3-static-lens-worker.md:169
still said TC1/V1 "waits for Q-Reification and the carrier landing", contradicting
the same brief's lines 15-19 + 148-153 saying Dag IS the carrier and no separate
carrier lands.

Fixed:
1. e6-g1a brief line 167-170 paragraph: clarified V1 waits for consumer-wiring
   work (lens fold consuming Dag via .dag body authority through Evaluator), NOT
   for a carrier-introduction.
2. r3-program-plan.md:954 Q-PAFS row text was the same shape: "Resume after
   Q-Reification + ReflectedProgram<T>" — contradicted my new Q-Reification row
   in the same diff. Updated: Q-Reification STOP CLEARED 2026-05-07 (Option A);
   remaining hold = Branch B η non-vacuity only.

Out-of-scope-for-this-PR: docs/briefs/r3-pr-e6-g1a-option3-feasibility-probe.md
contains 4 stale cites but is not modified in this PR; stale-on-main can be
swept in a follow-up if needed (single source of truth is the e6-g1a-static-lens
worker brief, not the feasibility probe per Q-PAFS Path A acceptance).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #2 + #3

codex BLOCKING at gunbc#2079 line 22: my brief mis-read services.dag:28-36.
The text actually says "No separate InputFieldRef carrier is introduced here,
since ParamToken.name already carries the same shape and adding a wrapper would
duplicate without strengthening the structural invariant" — i.e., InputFieldRef
does NOT exist; the comment REJECTS the wrapper.

Fixes:
1. Substrate observation #2 reframed: no FieldRef-shaped carrier exists at HEAD;
   services.dag:28-36 precedent argues against wrapper unless it strengthens
   structural invariant. New (a)/(b) STOP-and-PING:
   (a) follow services.dag precedent — wire_tag_field: String + key invariant
       on wire_tag_values + fixture-load fail-closed check;
   (b) introduce typed FieldRef — must justify per "duplicate without
       strengthening" test.
2. Carrier shape (line 19): wire_tag_field: FieldRef → {String|FieldRef}
   pending observation #2 resolution.
3. Substrate observation #3 reframed: InternallyTaggedObject asymmetry is
   conditional on path (b); under path (a) no asymmetry exists. Trigger
   correspondingly conditional. Removed stale "InputFieldRef classified" trigger
   clause.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — consolidate split per-variant maps into single keyed entry

openai-pro REQUEST_CHANGES at gunbc#2079: CoproductProjection shape split
per-variant data across two parallel maps (variant_field_projections +
wire_tag_values), admitting illegal states where keysets drift (P2 boundary
discipline / illegal-states-unrepresentable).

Fix: introduce CoproductVariantProjection { field_projection, wire_tag_value }
as the per-variant keyed value; CoproductProjection.variant_projections becomes
Map<VariantId, CoproductVariantProjection>. Single keyed authority per variant.

Director's binding constraint #2 enumerated the two fields separately but said
"refine in implementation as ergonomics demand" — consolidation preserves the
substantive constraints (typed WireTagValue leaf, structural per-variant
projection) while enforcing keyset alignment by carrier shape.

Empty-payload variants encoded via FieldProjection::Empty constructor (or
analog), not via map-absence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP-and-PING umbrella

openai-pro REQUEST_CHANGES at gunbc#2079: 2 BLOCKING findings.

1. Path (a) at line 43 still referenced "Map<VariantId, WireTagValue> key invariant
   on wire_tag_values" — that's the superseded split-map vocab; the consolidated
   shape is Map<VariantId, CoproductVariantProjection> on variant_projections.
   Path (a) now references the consolidated map; per-variant WireTagValue lives
   inside CoproductVariantProjection.

2. Pre-ratification umbrella at line 36 said "all 3 dispositions pre-ratified,
   proceed without re-pinging" — but observation #2 was re-opened after the
   codex InputFieldRef finding and explicitly says STOP-and-PING. Contradictory.
   Umbrella now scoped: observations #1 + #3 are pre-ratified; #2 is re-opened
   STOP-and-PING — worker MUST escalate before choosing path (a) vs (b).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof canvas — 4-residual coproduct-dissolution audit

Director ratified split disposition at gunbc#828 #issuecomment-4394696074:
descent_execution_proof STANDS ALONE (consumer-side termination-contract
substrate function with fail-closed residual enumeration; folding into
T-E-P-Producer-Broadening explicitly rejected — different concern axis).

Canvas surfaces 3 carrier-shape options for the residual enumeration per
Director's coproduct-dissolution audit suggestion:

α: 4-variant coproduct verbatim from §10.3 row 966 (Missing | Unknown |
   Incomplete | NonStrict)
β: 3-axis dimensional product (presence × completeness × strictness)
γ (recommended): reuse DescentEvidence at termination.dag:14-17 for
   "absent/unknown" via EvidenceUnknown(DescentEvidence) payload-variant +
   separate EvidenceIncomplete — ratchets variant count 4 → 2 via dimensional
   folding while honoring services.dag "no parallel wrapper" precedent.

Mgr recommendation γ; β rejected unless 3 axes provably compose orthogonally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authority map, no new enum variant

codex BLOCKING (post-merge of #2079, on commit 85ceb85a — same brief is now on
main): my Row #6 disposition told the worker to introduce a new
BootstrapAuthority::Pipeline variant ("extend the enum if needed"). That
violates P2 single-authority — src/v3/std/bootstrap_authority.dag:90 already
has "src/v3/compiler/pipeline.dag": CompilerAuthority, classifying pipeline.dag
under the existing CompilerAuthority variant. The :14-17 comment is explicit:
"the path itself is the BootstrapAuthoritySet map key; variants carry no
duplicate path payload" — single authority, not extension-by-variant.

Fix: Row #6 now instructs worker to derive the typed key from the existing
bootstrap_authority-map witness (BootstrapAuthorityKey threading the existing
CompilerAuthority classifier), refining the constructor surface if needed —
NOT introducing a new enum variant. STOP-and-PING criteria updated to forbid
new-variant resolution under any path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof worker brief — γ ratified (2-variant residual)

Director ratification at gunbc#828 #issuecomment-4395060514:
- DescentResidual = EvidenceUnknown(DescentEvidence) | EvidenceIncomplete
  (4 → 2 dissolution: Missing+Unknown fold via DescentUnknown injection;
  NonStrict folds via NonIncreasing wrap; Incomplete retained — different
  concern axis from evidence-lattice)
- DescentEvidence 3-variant lattice at termination.dag:14-17 confirmed as
  authoritative composition target
- Type signature from §10.3 row 966 confirmed verbatim-binding

Director-asked canvas-shape verification absorbed: worker STOPs if
EvidenceIncomplete decomposes into payload-variants (timeout / depth-bound /
evaluator-error-during-proof-construction); proceeds as 2-variant otherwise.

7 same-slice acceptance gates incl Evaluator E2 #1971 consumer wiring in same
PR + §10.3 row 966 row-text refresh to cite γ-disposition.

Worker pin: quick-koi-190 (pre-authorized per §10.3 row 966).

Auto-spawn HOLD per L-sized threshold; surgical-recreate path ratified
case-by-case if critical path blocked.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): descent_execution_proof — narrow EvidenceUnknown payload via NonStrictEvidence subset; delete superseded canvas

openai-pro REQUEST_CHANGES at gunbc#2105: 2 findings.

1. BLOCKING (LAYER MODEL / illegal states unrepresentable): worker brief
   shape `EvidenceUnknown(DescentEvidence)` admitted EvidenceUnknown(Strict)
   even though the canvas itself acknowledged Strict-isn't-a-residual as
   illegal. P2 requires API-level enforcement, not prose convention.

   Fix: introduce typed subset `NonStrictEvidence = NonIncreasing |
   DescentUnknown`; residual now `EvidenceUnknown(NonStrictEvidence)` —
   illegal-states-unrepresentable by construction. NonStrictEvidence lands in
   same file as DescentResidual; composes with existing 3-variant
   DescentEvidence via inhabitation, not re-definition.

2. NON-BLOCKING (live-state drift): canvas + worker brief both visible with
   "ratification needed" vs "ratified" status — same P2 single-authority
   shape as the S5 canvas/worker-brief co-existence at #2079.

   Fix: delete docs/briefs/r3-substrate-descent-execution-proof-canvas.md
   (worker brief frontmatter already names it as superseded; with canvas
   gone the live authority is unambiguous).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): descent_execution_proof — section-anchor cite for §10.3 row

codex BLOCKING at gunbc#2105 line 47: my brief cited "§10.3 row 966" but the
actual line is now 986 (after my Q-Reification row insert in PR #2079 shifted
§10.3 by 20 lines). Reviewer's "no such section" claim is wrong on substance
(file + section + row all exist) but the line drift IS real.

Fix per feedback_section_anchors_over_line_numbers (Director calibration in
gunbc#2079): replaced all "§10.3 row 966" with "§10.3 Q-EVAL-Descent-
Termination-Contract row" — name-anchor instead of line-anchor, drift-immune.
5 occurrences cleaned (closure predicate, acceptance gate #3, gate #5, STOP
criterion, worker pin justification). Stylistic "row row-text" repetition
collapsed to "row text".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> composition shape (#1957)

Pre-staged per Director endorsement of T-CostLens-Composition canvas-shape
authoring. Surfaces 3 composition options for the Lens<SymbolicCost> instance:

α: two separate lenses, externally joined — REJECTED (violates §1.8 gate #39
   no_coercion_cost_dimension by construction)
β: single Lens<SymbolicCost> with composed witness in read — strong but
   requires Lens<C> carrier-shape refactor (target-context threading)
γ (recommended): Lens<SymbolicCost> reads structural cost via algebra-fold +
   target-realization composed via existing Lookup<SymbolicCost> substrate at
   lookup.dag:48-60 — preserves generic Lens<C> carrier; satisfies all 4 §1.8
   gates (#37-40) by construction; aligns with feedback_audit_adjacent_authority_first

Adjacent substrate verified at HEAD: lens.dag:70-77 (Lens<C>), algebra.dag:12+
(SymbolicCost 7-variant + Semiring), lookup.dag:48-60 (Lookup<SymbolicCost> +
MissingCost lens-boundary).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scope-narrowing

Pre-staged per Director endorsement. Q-Workflow-As-Data-Carriers (§10.3 row 983)
named 5 carriers; grep-verified at HEAD that 4 of 5 ALREADY EXIST in
dsl/extdeps/github/actions.dag (218 lines). Only WorkflowSecret<Name> is
wholly net-new substrate.

Surfaces 3 options:
α: maximalist 5-carrier introduction in dsl/std/workflow.dag — REJECTED
   (admits parallel-representation debt vs audit-receipt #1771 reuse-first
   directive)
β (recommended): minimalist — only WorkflowSecret<Name> + Cron<Schedule>
   refinement net-new; lens consumes extdeps.github.actions directly. Honors
   feedback_audit_adjacent_authority_first.
γ: like β + WorkflowObservationAnchor for typed lens-consumption-shape;
   natural ratchet from β if evidence accumulates.

Sequencing: dispatch-ready post-T-LBP COMPLETE per §S4 design-schedule:95;
brief authoring lands in advance per pre-staging discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens-Composition worker brief — γ ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395691775:
- γ option ratified (Lens<SymbolicCost> + Lookup<SymbolicCost> composition)
- Lens<C> generic at lens.dag:70-77 confirmed authoritative (no refactor in scope)
- symbolic_cost_dimension: AnalysisDimension<SymbolicCost> defers to separate
  Dimensions sub-lane

Critical reframing absorbed: src/v3/lenses/cost.dag ALREADY EXISTS (status:
STRUCTURALLY TERMINAL; BEHAVIORALLY PROXY). T-CostLens-Composition is
behavioral-completion + target-realization-wiring, NOT P1 carrier introduction.
Worker reads existing lens; advances PROXY → BEHAVIORALLY COMPLETE via
Lookup<SymbolicCost> composition.

8 same-slice acceptance gates incl §1.8 #37-40 + #70 demonstration + lens
status header refresh + §10.3 row text refresh.

Out-of-scope (deferred per Director): symbolic_cost_dimension; Lens<C>
generic refactor (STOP-and-PING if implementation reveals need).

Canvas deleted per single-authority discipline (same precedent as S5 +
descent_execution_proof canvas deletions).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Delete superseded T-CostLens canvas (worker brief is single live authority)

* docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas

Director ratification at gunbc#828 #issuecomment-4395945465: 4 asks confirmed:
1. β ratified (minimalist reuse-first)
2. #1771 audit-receipt binding precedent confirmed
3. WorkflowSecret<Name> folds into dsl/extdeps/github/actions.dag (provider-
   specific scope; NOT new dsl/std/ file unless cross-provider evidence)
4. §1.8 gates #54 + #55 split into separate slices (slice 2 = timing-and-pattern;
   slice 3 = ci_workflow_modeled_as_dag)

Slice 1 net-new substrate (only):
- WorkflowSecret<Name> + SecretScope carriers
- CronExpression + CronField (typed refinement of existing
  WorkflowTrigger::Schedule { cron: String } at actions.dag:43)

Other 4 carriers from §10.3 row 983 reused as-is from extdeps.github.actions
per audit-receipt #1771 directive.

6 same-slice acceptance gates incl no-parallel-representation grep + gate
#53/#62/#63 advancement + bootstrap regen + clippy.

Cross-provider STOP-and-PING per Director ask #3 caveat: worker greps adjacent
provider work for WorkflowSecret-shape evidence; surfaces if found before
finalizing fold-into-extdeps.

Canvas deleted per single-authority discipline (S5 + descent_execution_proof +
T-CostLens precedent).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demo (#1952) complexity-contract compile-error worker brief

Pre-staged execution brief per Director endorsement of T-LAS demos via direct
worker brief path (no canvas — design-lock at docs/design-lens-application-
surface.md specifies fixture shape verbatim at line 292).

7 same-slice acceptance gates: fixture program (O(n²) body + Enforce O(log n)
budget) + TestClaim assertion + diagnostic structural validation + no
regression on T-LBP cementing + bootstrap regen + clippy + §1.8 #92
advancement.

Hard prerequisites STOP-and-PING: T-LAS Slice A landed (gates #88-#91) AND
T-LBP complexity-lens BEHAVIORALLY COMPLETE (gate #79). Worker does not
author against partial substrate.

Sibling demos #1953 (CRDT cost) + #1954 (memory-peak cost) share the same
hard-prerequisite + TestClaim shape pattern — could dispatch as 3 sequential
PRs or single multi-demo PR (worker's call at dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LAS Demos #1953 + #1954 — cost-basis sibling worker brief

Pre-staged sibling brief covering both cost-basis demos (CRDT cost basis +
memory-peak cost basis) per Director endorsement of T-LAS demos via direct
worker-brief path. Single brief for two demos because they share:
- Hard-prerequisite pattern (T-LAS Slice A + T-LBP cost-lens BEHAVIORALLY COMPLETE)
- TestClaim + Diagnostic structural validation shape
- apply_lens(cost, ...) Enforce mode

Sibling of #1952 brief (complexity-contract compile-error). Worker's call at
dispatch on multi-demo PR vs sequential PRs (Mgr ratification needed if going
multi-demo).

#1953 (CRDT) substrate per design §4.2 + cost-basis-declaration audit at
docs/audit/t-user-authored-cost-basis-discipline-worked-examples.md.
#1954 (memory-peak) substrate per design §4.3; STOP-and-PING if
Dimension<SymbolicCost> substrate (deferred to Dimensions sub-lane per Director
ratification at gunbc#828 #issuecomment-4395691775) not yet landed.

6 same-slice acceptance gates per demo + same STOP-and-PING discipline as #1952.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-CostLens — update Sub-issue from #1957 to #2141 (post-surgical-recreate)

PM executed Director's surgical-recreate ratification (gunbc#828
#issuecomment-4397693699) at 17:54:43Z: closed #1957, created fresh #2141 to
trigger pollAutoSpawn fresh-creation path. Worker fierce-ram-21 (#2153) spawned
on #2141.

1-line brief update per Director's queued-action commitment: brief now
references #2141 + cites surgical-recreate authority. #1957 closed-as-superseded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context canvas (β-extended substrate-shape question)

Director α-revised supersession at gunbc#828 #issuecomment-4400920572 elevated
β-extended path (introduce first-precedent .dag-side fold-over-realization-rows
+ name active-target authority shape) from slice-tier to canvas-tier.

Authored per Q-PAFS template:
- Substrate-state at HEAD grep-verified (Lens<C>.read no target-context;
  zero .dag-side fold-over-realizations precedent; 15+ lens instances using
  generic Lens<C>)
- Binary question: should .dag-side lenses receive target-context for
  target-keyed reading?
- Options matrix: (i) LanguageSpec param to fold; (ii) per-target lens
  instances [parallel-representation debt]; (iii) global accessor [REJECTED
  global-state anti-pattern]
- Mgr provisional preference: (i)
- Cross-cutting: cost.dag load-bearing; emission_provenance.dag secondary;
  other 13+ lenses target-agnostic

Framework discipline anchors per Director corrections:
- feedback_same_slice_dissolution_discipline
- feedback_parallel_representation_debt
- feedback_abstraction_layering (sibling canvas)

Sibling canvas (ε path): q-cost-composition-layering-canvas.md authoring
follows. Both canvases together address deeper cross-cutting axis: does
target-context belong .dag-side (β-extended) or emit-side (ε)?

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Cost-Composition-Layering canvas (ε substrate-shape question)

Sibling canvas to q-lens-target-context-canvas.md. Director α-revised
supersession at gunbc#828 #issuecomment-4400920572 elevated ε path (Rust-side
cost-composition wiring; preserves cost.dag PROXY) from slice-tier to
canvas-tier.

Authored per Q-PAFS template:
- Factoring claim: cost = (target-agnostic-shape SymbolicCost algebra) ×
  (target-specific-values per-primitive realization-cost data loaded Rust-side)
- Test against feedback_abstraction_layering (Director-named anchor at
  gunbc#828 c#4400921658): pure objective concepts × language-agnostic
  LanguageSpec × emit-side composition. Compliance test for each layer.
- Pro factoring (ε structurally honest): SymbolicCost algebra is target-
  agnostic at HEAD; Rust-side composition is natural home; #38/#39 substrate-
  already-aligned per Slice 1 finding.
- Con factoring (ε is parallel-representation debt): N parallel Rust-side
  compositions if multiple lenses need target-context; lens-framework
  abstraction stops at substrate boundary; future lenses hit same dilemma.

Mgr provisional reading: factoring honest for COST specifically; NOT
generalizable. ε right framing IF cost is the singular need + factoring
holds. If N>1 target-context-needing lenses surface, β-extended (option
(i) from sibling canvas) becomes the right path.

Director ratification ask: 3-way choice
  (ε) Cost-specific Rust-side composition; preserves cost.dag PROXY
  (β-extended option (i)) Lens<C> refactor for LanguageSpec parameter
  (both sequenced) ε now for cost; β-extended later if N>1

Framework discipline anchors:
- feedback_abstraction_layering (Director-named for this canvas)
- feedback_parallel_representation_debt
- feedback_same_slice_dissolution_discipline

Canvas-pair complete; sibling canvas + this canvas address the deeper
cross-cutting axis: target-context belongs .dag-side (β-extended) or
emit-side (ε)? Director ratification across both informs T-CostLens
follow-on slice + downstream lens architecture.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: ε ratified canonical for cost; β-extended deferred to N=2 — gate updates

Director ratification at gunb-ai/gunbc#2181 #issuecomment-... :
- (ε) RATIFIED standalone for cost composition (canonical-not-transitional)
- (β-extended option (i)) DEFERRED to N=2 trigger event (second lens with
  target-context need beyond cost)
- ("both sequenced") REJECTED as bridge-with-named-dissolution anti-pattern

Same-slice acceptance gates landed:

1. Q-Cost-Composition-Layering canvas: status updated from "ratification
   needed" → "Director-RATIFIED 2026-05-07 (ε standalone; canonical-not-
   transitional); PROPOSAL maturation pending"
2. Q-Lens-Target-Context canvas: status updated from "ratification needed"
   → "DRAFT/DEFERRED 2026-05-07; reopens on N=2 trigger event" (second lens
   with substantive target-context need; emission_provenance most likely
   candidate per cross-cutting analysis §3)
3. r3-program-plan.md gate-table rows #37 + #40 + #70: ε path ratified;
   close via Rust-side composition reading abstract SymbolicCost × per-
   primitive realization-cost in T-CostLens follow-on slice
4. r3-program-plan.md §10.3 T-CostLens-Composition row: ε ratified for
   #37/#40/#70; β-extended deferred per N=2 trigger
5. v3-lens-capability-register.md cost.dag row: ε disposition cited; #2175
   continues as cross-cutting umbrella tracker

Closed-system disposition per Director: if N=2 condition never fires,
β-extended never fires — structurally correct under closed-system design.

Framework discipline anchors honored:
- feedback_abstraction_layering: ε respects layering (objective concepts
  pure; target-specific values flow at emit time per Layer-3 honesty test)
- feedback_parallel_representation_debt: bounded to N=1; reopens at N=2
- feedback_same_slice_dissolution_discipline: ε ratified canonical, not
  transitional
- feedback_construction_over_ratchets: substrate-shape question answered
  structurally
- feedback_substrate_principle_audit: substrate-fact authored at canvas-
  tier; ratification follows P1 procedure

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvas inventory grounded in live src/v3/lenses/ registry

codex BLOCKING at gunb-ai/gunbc#2181 (sha 00551a80): Q-Lens-Target-Context
canvas inventory was "copied from expected lens set instead of live
src/v3/lenses/ registry"; emission_provenance trigger references not
grounded in live file content.

Same shape of error as 3 prior BLOCKING reversals (Q-Reification, S5
DeclarationRef, T-CostLens merge-content). Substrate-state-grep is being
treated as retrospective-correction rather than prerequisite. Tightening:
this is the 4th occurrence; should be hard-prerequisite-discipline going
forward.

Fixes:

1. Q-Lens-Target-Context inventory section: replaced approximate "15+
   lens instances" framing with exact `ls`-grep registry (15 .dag files
   listed by name), notes infer_helpers + lower_helpers are helper
   modules authoring shared structural fns rather than top-level lens
   instances.

2. emission_provenance.dag analysis grounded in HEAD file status header:
   STATUS = STRUCTURALLY TERMINAL; LENS-INSTANCE FIXTURE-BOUND; BEHAVIORALLY
   DEFERRED. `read` body is fail-closed Empty stub. Lens does NOT currently
   read target-context inside fold; producer-side instrumentation records
   target-specific entries consumed via standard framework. Reframed as
   "ungrounded at HEAD" rather than "POSSIBLY target-context need" —
   re-evaluates at producer-wiring landing.

3. Net finding: N=1 confirmed at HEAD (cost.dag only); N=2 is empirically
   open pending lens-completion cycles, NOT pre-claimable.

Plus non-blocking improvement: Q-Cost-Composition-Layering line 9 stale
`#issuecomment-...` placeholder replaced with concrete ratification
comment id `#issuecomment-4401584012`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): fix Director-ratification-ask typo + #37 gate-id clarification footnote

cursor APPROVE_WITH_COMMENTS at gunb-ai/gunbc#2181 (sha 4209eb7f) flagged 2
NON-BLOCKING items + 1 exploratory:

1. (NON-BLOCKING) Q-Cost-Composition-Layering line 69: `## Directorratification ask` → `## Director ratification ask` (whitespace typo)
2. (NON-BLOCKING) Q-Cost-Composition-Layering line 9 placeholder `#issuecomment-...`: ALREADY ADDRESSED in commit `db88b1004` (replaced with `#issuecomment-4401584012`)
3. (Exploratory) Gate #37 id `cost_lens_reads_target_realization` framing implies .dag lens body performs realization read; per ε ratification it's Rust-side composition consumer. Added clarifying footnote noting gate-id retention + Rust-side closure path; rename candidate post-follow-on-slice landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — absorb PM canvas-review concerns 1-3

Director relayed PM canvas review at gunb-ai/gunbc#2068 c#4401627536:

Concern 1 (RESOLVED via grep-verify): empirical N=1 confirmation. PM ran
`grep -lc 'TypeRealization|CallableRealization|MethodTemplateContract|
target_realization|realization_cost|LanguageSpec' src/v3/lenses/*.dag`;
only cost.dag has 3 hits, all 14 others have 0 refs (including
emission_provenance.dag which I'd previously framed speculatively).

Net-finding §3 updated with grep result inline + "N=1 empirically grounded"
framing replacing speculative "secondary candidate" language. Empirical
basis for DEFERRED β-extended disposition strengthened.

Concern 2 (Option (ii) multiplier framing): per-target lens instances
replicate the entire Lens<C> authoring surface — N×M × 4 (carrier + monoid
sequential + branch + iterate) authoring overhead. Updated Con bullet to
reflect the multiplier explicitly: 3 targets × 1 cost lens × 4 = 12 authored
fns; grows to 36 if 3 lenses need target-context. Cites
feedback_parallel_representation_debt as the P2 framing.

Concern 3 (Option (i) threading cost quantification): replaced narrative
"threading cost is real but manageable" with quantified breakdown — ~15
signature changes + 14 ignore-parameter patterns + 1 consumer + cementing-
test revalidation. Helps future Director ratification at N=2 trigger event.

All 3 amendments are docs-only refinements; ε ratification at gunbc#2181
c#4401584012 unchanged. Strengthens canvas as durable substrate-shape
decision record.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): canvases — collapse stale ratification-ask sections post-ratification

codex BLOCKING at gunb-ai/gunbc#2181 (sha be9a9c94): both canvases had stale
"Director ratification ask" sections after status headers were updated to
RATIFIED/DEFERRED. Per INVARIANTS P1 "Documentation Describes Live State" —
canvas internally presented both settled and unsettled authority.

Fixes:

1. Q-Cost-Composition-Layering line 69-76: "Director ratification ask"
   section collapsed to "Director ratification (RECEIVED 2026-05-07)" with
   ε ratified, β-extended deferred, "both sequenced" rejected. Three options
   recorded as historical with ratification cite. Eliminates the rejected
   "both, sequenced" line that conflicted with status-header "canonical-not-
   transitional" framing.

2. Q-Lens-Target-Context line 131-136: "Director ratification ask" section
   collapsed to "Director disposition (DEFERRED 2026-05-07; reopens on N=2
   trigger event)". Original ratification asks recorded as FROZEN; revisit
   at N=2 trigger event with then-current substrate-state grep. Eliminates
   live-now-ratify framing that conflicted with status-header DEFERRED.

Both canvases now single live authority — RATIFIED/DEFERRED dispositions,
no internal ratification-ask drift. Future re-ratification (Q-Lens-Target-
Context at N=2 trigger) refreshes options matrix at that point per
substrate-state-honesty discipline.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Lens-Target-Context — separate live N=1 from reopen-only future N=2

openai-pro APPROVE_WITH_COMMENTS at gunb-ai/gunbc#2181 (sha be9a9c94): canvas
line 127 mixed live N=1 authority with speculative N=2 candidate in one
current-state cost count.

Per P1 Documentation Describes Live State + P2 single-authority metadata:
the live count at HEAD is `cost × 3 targets = 3 per-target instances` (× 4
authoring-multiplier per Option (ii) Con = 12 fns). The `emission_provenance
× 3` figure is a reopen-only future scenario that materializes only if
emission_provenance becomes the second real target-context lens at producer-
wiring landing time.

Updated to separate the two clearly: live count + reopen-only future
scenario marked separately. Aligns with the grep-verified N=1 finding
established earlier in canvas §3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): T-CostLens worker brief — ε supersession header (γ retained as context)

PR #2181 merged at eff426de5 ratifies ε path canonical-not-transitional
for cost composition. Brief was authored under γ scope (.dag-side
Lookup<SymbolicCost> composition). Add binding ε supersession header at
top; retain γ section as historical context per single-authority
discipline. cost.dag stays PROXY under ε; composition is Rust-side
(abstract SymbolicCost shape × per-primitive realization values).

Authority: Director ratification at gunb-ai/gunbc#2181 #issuecomment-4401584012.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-Complexity-Composition-Layering canvas — DRAFT (factoring tested, ε precedent does NOT apply)

Director authorized canvas authoring at gunb-ai/gunbc#828 c#4402669133 as
parallel structure to Q-Cost-Composition-Layering (ε RATIFIED). Substrate-
grep on src/v3/lenses/complexity.dag at HEAD shows the factoring claim
DIFFERS from cost-lens:

- Cost-lens needed (target-agnostic shape × target-specific values)
  factoring → Rust-side composition (ε)
- Complexity-lens has NO target-specific axis; output is structural
  property of DAG topology + algebra-instance composition; substrate-
  native fully-on-.dag-side completion

Mgr provisional reading: ε precedent does NOT apply; complexity-lens
BEHAVIORAL COMPLETION is direct slice-tier substrate authoring (carrier
introduction follows SymbolicCost precedent + T-E-P P1 carrier
consumption). Director ratification ask: Q1 (factoring finding correct),
Q2 (slice-tier directly bypassing canvas), Q3 (fresh worker pin).

Cross-Mgr: Verification Mgr (#2075) pinged on v2-oracle snapshot capture
status (cross-cutting prerequisite for #1950/#1951 cementing dispatch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): T-LBP complexity-lens substrate-completion worker brief (Q1/Q2/Q3 RATIFIED)

Pre-authored brief for complexity-lens BEHAVIORAL COMPLETION substrate
work per Director Q1/Q2/Q3 ratification at gunb-ai/gunbc#828 c#4402714255.

Three deliverables: carrier introduction (ComplexityCost / WorkSpan /
AsymptoticClass following SymbolicCost precedent) + lens widening
(complexity.dag PROXY → COMPLETE) + T-E-P P1 carrier consumption
(DescentEvidence / CallPattern / SubValueRelation for asymptotic
classification of recursive-call behavior).

Indirect-variant dependency surfaced as worker-grep concern at slice-
authoring time (T-E-P P1 Slice 5+ pending; eager-bat-178 stream).

Cementing test (#1950) is separate downstream brief; v2-oracle snapshot
ownership pending Q4 cross-Mgr ratification.

Worker pin: fresh-pool pick at dispatch time (NOT eager-bat-178 per
Director Q3 framing; NOT fierce-ram-21 busy with cost-lens ε).

Same-window-dispatch discipline applies post-canvas-merge (PR #2197).

Pre-authored vs pre-known discipline applied per
feedback_pre_known_vs_pre_authored_briefs.md memorialized 2026-05-08.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): rewrite complexity-lens brief consuming live design authority (codex BLOCKING fix)

Codex BLOCKING (3 findings) at #2199 sha 7a8bb6dc:
1. Brief authored against missing canvas instead of reconciling with
   docs/design-complexity-lens-behavioral-completeness.md (which exists
   at HEAD with comprehensive substrate spec)
2. Producer coverage treated as optional corpus scope; should be hard
   T-E-P-Producer-Broadening prerequisite
3. Stale/non-in-repo planning authority cited; should be r3-structure.md
   row 146 (T-LBP slice 1)

All three BLOCKING findings VALID — substrate-grep-before-authoring
discipline failure on my part (feedback_substrate_grep_before_authoring
already memorialized; violated own discipline).

Rewrite delegates carrier shape, dimension wiring, and consumer rewrite
to live design doc §§1.1-1.6 verbatim:
- §1.1 SymbolicCost — already at algebra.dag; no change
- §1.2 SizeVariable — display_name enrichment
- §1.3 work_dimension + span_dimension — two AnalysisDimension instances
- §1.4 AsymptoticClass + BoundedLattice instance
- §1.5 Certainty (cost-aware composition; no lattice)
- §1.6 cost_bound_to_symbolic projection
- §1.7 ComplexitySummary record + lens widening

T-E-P P1 hard prerequisite per design's authority discipline + r3-
structure.md row 146; STOP-and-PING if T-E-P P1 not COMPLETE at slice
authoring time. Authority cites updated to live r3-structure.md row 146.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas — DRAFT (canvas-tier P1 procedure per Q6 RATIFIED)

Director Q6 RATIFIED canvas-tier-required at gunb-ai/gunbc#828 c#4403163639
for PerfWithinBaseline TestPredicate variant authoring. Three substantive
substrate-shape questions resolved:

Q1 baseline shape: (a) literal-Int rejected as strict-mirror-of-CostBounded
defeats semantic load; (b) DeclarationRef-to-stored-data composes
LensOutputEquals + data X: SymbolicCost precedent at HEAD; (c) runtime-
fixture-injection over-authors. Mgr lean (b).

Q2 ComparisonOp composition: (i) reuse existing ComparisonOp via test-
runner-side resolution matches LensOutputEquals path; (ii) new relative-
op-set introduces parallel-representation debt. Mgr lean (i).

Q3 baseline-storage scope: (α) in-scope slice authors example data; (β)
out-of-scope variant-only slice + PB consumer authors baseline data
matches existing layering. Mgr lean (β).

Combined Mgr lean: Q1(b) + Q2(i) + Q3(β) — variant authored as
compositional extension; baseline-storage is PB consumer-tier work.

Cross-Mgr: PB Mgr #2138 worker (crisp-swift-433) holds dispatch on #2204
land; T-Tier3-Dissolution #2085 R-4 prereq encoded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas REVISED (supersedes wrong-shape original)

Director disposition at gunb-ai/gunbc#828 c#4403265220 authorized
supersession after BLOCKING at PR #2209 c#4403246233 verified VALID:
original canvas conflated symbolic SymbolicCost (cost-lens substrate)
with wall-clock measured median/p99 baseline (T-Tier3 perf gate
substrate per docs/r3-structure.md:225 + :461 Director-locked 2026-04-28).

Revised canvas frames as two-path ratification:
- P1 author full perf-budget substrate in-R3 (multi-slice; pattern-5
  genuinely-novel substrate-fact-introduction)
- P2 explicitly post-R3 per Director-locked recommendation (zero in-R3
  effort; structural close per r3-structure.md:461 'R3 deliverable is
  structural close; perf is downstream')

Mgr lean: P2 — Director-locked recommendation explicit; trigger-
condition ('someone authors perf-budget claim with concrete numbers
and tooling') not met; R3 horizon constraint argues against multi-
slice perf-budget substrate adding to 5-orthogonal-dependency picture.

Original canvas at q-perf-within-baseline-canvas.md retained with
SUPERSEDED-BY header per durable-decision-record discipline.

5th discipline-failure of 2026-05-08 cycle: substrate-grep verified
substrate-precedent but missed consumer-side requirement at canonical
authority doc; Director self-flagged symmetric two-axis verification
gap; canvas-finding-taxonomy needs precondition 'consumer-side
requirement grep-verified at canonical authority doc'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-PerfWithinBaseline canvas-revised — correct trigger-condition framing per Director c#4403297623

Director caught second-axis grep failure on revised canvas: my P2
reasoning #1 ("path-trigger condition for P1 is not met") was
structurally wrong. Existing tooling at HEAD substantially meets the
Director-locked 2026-04-28 trigger-condition ("someone authors the
perf-budget claim with concrete numbers and tooling"):

- docs/briefs/r3-pb-tier3-perf-budget-worker.md
- docs/audit/c1-tier3-perf-budget-readiness-matrix.md
- src/v3/compiler/benches/tier3_mirror_perf.rs
- docs/audit/c1-tier3-baseline-capture-procedure.md
- docs/audit/c1-r3-canonical-bench-host-decision-matrix.md

Plus thresholds (≤2× median, ≤5× p99) + capture discipline (N=3 min,
N=5 preferred) + canonical bench host option matrix.

P1 is bridging existing tooling to substrate (compositional-extension),
NOT multi-slice greenfield genuinely-novel pattern-5 as originally
framed. Smaller scope than canvas-finding-taxonomy pattern 5 implies.

Path-call genuinely depends on PB Mgr's R-3 (canonical CI bench host)
+ R-7 (tier3_baseline.json baseline-capture path) decisions per their
audit response at c#4403059897. Path-call DEFERRED to cross-Mgr
coordination outcome with PB Mgr (#2074); Substrate Mgr surfaces with
corrected framing this turn.

Sixth discipline-failure of cycle (mine, second-axis grep gap on
existing-tooling state); same-class as Director's first-axis grep gap
on consumer-side requirement at the prior turn. Memorialized as
two-axis verification discipline anchor.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-ValueBody-Drift-Resolution canvas — DRAFT (codegen-generation lean)

D1 substrate-shape question per Q-ValueBody-Isomorphism RATIFIED at
gunb-ai/gunbc#828 c#4403972737. Variant-inventory readiness input from
PR #2218 (merged 2026-05-08) confirms drift: Rust 5 variants vs
substrate 3 constructors; asymmetry on Scalar+List Rust-only +
Map payload-parity-with-semantic-gap.

Two-axis verification at HEAD:
- Substrate-precedent: codegen tooling exists (regen_bootstrap_emit;
  5 _generated.rs files; regen_bootstrap binary). Pattern-3 strict-
  mirror codegen extension applies; no pattern-5 P1 procedure.
- Consumer-side requirement: V1 worker brief explicitly names mirror-
  parity-vs-codegen-generation as D1 path-pair.

Mgr lean: (b) codegen-generation. Path (a) mirror-parity perpetuates
parallel-representation debt; (b) dissolves the dual-taxonomy class
by construction (substrate canonical, Rust codegens). Map dup-key gap
handled via (ii) Rust-side post-codegen wrapping (substrate stays
minimal).

Director ratification ask: D1 (b) + D1-followup (ii).

Carrier slice path post-ratification: extend regen_bootstrap_emit;
add Scalar+List constructors to substrate; regen + remove hand-Rust
enum; handle Map dup-key per ratified followup. Worker pin fresh-pool
per same-window-dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(proposals): Q-ValueBody-Drift-Resolution canvas amend authority cite (codex BLOCKING fix)

Director ratified (α) amendment-PR at gunb-ai/gunbc#828 c#4404398425
post-codex-BLOCKING at PR #2222 c#4404360699.

Canvas originally cited regen_bootstrap_emit.rs as codegen authority
for ValueBody runtime mirror; corrected to scripts/regen_runtime_mirrors.py
which is the substrate→Rust runtime-mirror generator (reads substrate.dag,
emits dag_scalar_generated.rs etc.). regen_bootstrap_emit.rs is a
separate codegen system that generates bootstrap_generated.rs (bootstrap
parser/lower compile snapshot).

D1 (b) codegen-generation ratification UNCHANGED; only authority-path
cites corrected. Carrier slice path at canvas §6-step plan now references
correct runtime-mirror generator. Canvas inline notes mark amendment
location for future-reader audit trail.

8th cycle-tier framing-failure (Mgr-tier; same fine-granularity gap
parallel to Director-tier failure at c#4404256128). Two-axis verification
discipline applied at insufficient granularity (verified codegen-tooling-
exists but didn't disambiguate against bootstrap-vs-runtime-mirror systems).

Discipline anchor refinement: when canvas cites a codegen system /
tooling / authority path, identify the SPECIFIC generator/handler for
the target-file-class. Don't accept 'tooling exists' at coarse granularity.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: reconcile cross_target_coverage emission_path_projections post-population drift

cross_target_coverage.dag:179 + sg0_census_test.rs:355 still described
emission_path_projections as `(empty data state)` / `== []`, but the
data block at cross_target_coverage.dag:186 is populated with 41 Phase-1
rows (Rust 13 / Python 16 / Go 12). Update both comment sites to reflect
the populated state. P1 Modeling Faithfulness — comment-drift only, no
behavior change.

Surfaced by gentle-newt-665 R3 Debt-Paydown ROADMAP audit at gunb-ai/gunbc#2062;
absorbed into Substrate lane (#1939) per L6 emission_path_projections
carrier ownership.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix: pad cross_target_coverage.dag comment to preserve byte offsets

Previous comment edit changed line 179 length 76→75, shifting
SourceSpan byte offsets in bootstrap_generated.rs by 1 and breaking
regen_bootstrap --verify in CI. Pad with one extra dash to restore
original 76-char length; comment text intent unchanged.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* fix(canvas): clarify Source param doesn't carry subject identity (P2)

Reviewer flagged on PR #2333 inline review: parametric form
WorkflowObservationAnchor<BehaviorId, TimingMeasurement> would create
redundant subject-identity authority if TimingMeasurement carries
subject identity (P2 violation). Clarify Q-WAD-S2-Anchor (b) so Source
parameter is observed-payload-only; subject identity is owned solely
by Subject parameter.

In worker's actual PR #2360 shape, TimingMeasurement is variant-typed
report state (Observed { nanoseconds } | Missing | ...) and does NOT
carry subject identity — concern is theoretical there but worth
clarifying canvas language for clean Director ratification.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): correct fail-closed analysis for LensEnforcement.violates signature

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:90):
LensEnforcement.violates signature is (Budget, Budget) -> Bool per
src/v3/std/lens_application.dag:100 — does NOT see raw Output.
Original canvas claim 'fail-closed: violates = Output != Observed'
was structurally wrong. Updated:

- (a) clarified: projection step (Output → Budget) must fabricate
  violating Budget for non-Observed variants (option (a)(i)) OR
  substrate-extend the violates signature (option (a)(ii)) which is
  canvas-tier and cascades across all lens consumers.
- Added option (c) reflecting worker tidy-raven-610 PR #2360 shape:
  Output folded into TimingMeasurement carrier directly, Budget
  projection handles fabrication naturally.

Status: shape ratification still pending Director per #828 c#4412018726.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): add 🟢 dissolution classification to TimingObservationOutcome variants

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:86):
proposed sum has no 🟢/🟡/🔴 dissolution receipt per INVARIANTS P5 /
modeling-discipline.md §coproduct dissolution. Worker could land
unclassified coproduct.

Added 🟢 GREEN (terminal) classification to both option (a)
TimingObservationOutcome and option (c) folded TimingMeasurement —
four variants exhaust externally-attested observation states; no
richer-source-extraction path exists at the workflow-observation
boundary. Worker .dag declarations MUST carry the 🟢 marker comment
per modeling-discipline.md:132.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): correct Q-WAD-S2-Placement to src/v3/std/ (not dsl/std/)

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:108):
recommending dsl/std/timing_lens.dag conflicts with src/v3/std/lens.dag:17-21
v3-only-carriers convention. Worker would land substrate in wrong layer.

Earlier canvas claim 'T-LBP / T-CostLens / T-LAS lens carriers all live in
dsl/std/' was factually wrong — they live in src/v3/std/ and src/v3/lenses/.
Corrected to src/v3/std/timing_lens.dag throughout. Worker PR #2360 already
placed at correct path; canvas now matches.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): make six gate #55 invariants concrete fields on anchor (P2)

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:75): the
recommended <Subject, Source> parametric shape only named type params
and didn't assign digest/producer/observer/prover/timestamp/run-id/
report-state to a single carrier — gate #55 facts wouldn't flow forward
under P2 boundary discipline.

Fixed: Q-WAD-S2-Anchor (b) now shows explicit six-invariant field
schema as concrete fields (subject/artifact_digest/producer_id/
observer_id/prover_id/attached_at/workflow_run_id/observation_outcome)
with Subject + Source as type parameters for variable parts only.
Notes worker tidy-raven-610 PR #2360 flat shape is already
gate-#55-compliant at the field level; convergence path is adding
type parameters to the flat shape (minimal rework).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): correct convergence assessment — invariant 5 split-authority in worker shape

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:96): claiming
worker's flat anchor shape gate-#55-compliant drops invariant 5
(observation_outcome / report-state) from the anchor. Worker's
TimingMeasurement variants carry report-state on the payload, not on
the anchor — splits P2 single-authority for invariant 5.

Fixed: convergence assessment now correctly identifies 5/6 invariants
on anchor + invariant 5 split. Path requires TWO edits not one:
(1) add <Subject, Source> type parameters to anchor; (2) add
observation_outcome: ObservationOutcome<Source> field to anchor itself.
This collapses Q-WAD-S2-Output (c) folded shape back to (a)(i)
separate-projection — trade-off documented (single-authority preserved
at cost of one extra type).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): reject (a)(i) Budget fabrication per P3/C-8 fail-closed (canvas:118)

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:118):
recommending projection fabricates violating Budget for non-Observed
states violates INVARIANTS P3/C-8 fail-closed discipline — erases
typed Missing/Ambiguous/Stale failure evidence into a plausible budget
value. Consumers downstream of violates can't distinguish 'budget
exceeded by observed value' from 'no observation existed'.

Fixed: (a)(i) REJECTED with explicit P3/C-8 rationale. Added (a)(iii)
Result-typed projection with auto_violate_on_left bit — smaller
substrate change than (ii) full-signature-extension. Director-tier
disposition still required for (ii) or (iii); (i) no longer a viable
path.

Convergence implications for worker PR #2360 + canvas (c) folded
shape need re-assessment in next pass — (c) sidesteps the violates
signature collision but invariant 5 split-authority (per canvas:96
fix in 960a03f98) means observation_outcome belongs on anchor not
payload, which then re-introduces the violates-Output-visibility
question via ObservationOutcome typing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): propagate (a)(i) rejection across all recommendation/status refs

Earlier commit 594a4df9c rejected (a)(i) Budget fabrication per
P3/C-8 inline review. Updated remaining 3 refs to reflect:
- Q-WAD-S2-Anchor convergence trade-off line
- Q-WAD-S2-Output recommendation: now (a)(ii)/(a)(iii) pending Director
- Q3 (c) Status line: Director call is (a)(ii)/(a)(iii) vs (c)

(a)(i) is REJECTED throughout; Director-tier LensEnforcement substrate
change unavoidable for fail-closed-correct anchor-side report-state
carriage.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): correct invariant-6 claim — fail-closed needs LensEnforcement substrate-extension

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:91): claim
'all six invariants concrete fields on anchor' was wrong — invariant 6
(fail-closed) explicitly lives at LensEnforcement.violates layer, not
on the anchor. Without Q-WAD-S2-Output (a)(ii)/(a)(iii) substrate-
extension landing, gate #55 cannot close on 5/6 — would let consumers
attach observation facts without fail-closed evidence (P2/P3 violation).

Fixed: clarified 5/6 invariants on anchor + invariant 6 dependency on
Director-tier LensEnforcement substrate-extension. Gate #55 closure
explicitly cross-linked to canvas:118 escalation thread.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): Output (a) variants wrap Source not TimingMeasurement (P2)

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:112):
Output (a) Observed{value: TimingMeasurement} would wrap the
report-state-bearing TimingMeasurement type, duplicating
identity/attestation/report-state with the anchor's invariant 5
authority. Reopens P2 split-authority.

Fixed: Observed wraps payload-only Source (e.g., TimingPayload {
nanoseconds: Int }), NOT TimingMeasurement. Per Q-WAD-S2-Anchor
revised convergence: subject identity / attestation / report-state
on anchor; payload carries only observed-value-when-present.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): split gate #55 + canonicalize TimingPayload (parent BLOCKING b526a26f)

Reviewer flagged 2 BLOCKING on PR #2333 parent review at sha b526a26f:

Finding 1 (gate #55 mixes anchor-fact + fail-closed): added gate #55a/#55b
split — #55a = anchor carrier landed (worker scope); #55b = LensEnforcement
substrate-extension landed across all lens consumers (canvas-tier separate
dispatch, owner: Substrate Mgr).

Finding 2 (TimingMeasurement overload): added Naming canonicalization
section to Carrier inventory. TimingPayload = observed-value-only;
WorkflowObservationAnchor = observation record; ObservationOutcome = report
state; TimingObservationSet = lens C (per Q1 ratification). Earlier
TimingMeasurement references deprecated.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): rewrite Carrier inventory to reflect Director ratification of worker shape

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:35): old
carrier inventory still said TimingMeasurement owns subject identity +
observer attestation, contradicting revised anchor authority. Same-day
Director re-ratification at #828 c#4412301889 reversed the canvas (b)
recommendations and ratified worker tidy-raven-610's shape as-shipped:

- TimingMeasurement = Observed | Missing | Ambiguous | Stale
  (carrier-as-report-state; owns invariant 5 via variants)
- WorkflowObservationAnchor = timing-specific concrete fields
  (Q-WAD-S2-Anchor (a) ratified; owns invariants 1-4)
- TimingObservationSet = aggregation collection
- Lens<TimingMeasurement> per-observation

Fixed: rewrote Carrier inventory to reflect Director-ratified shape;
explicit invariant ownership (anchor: 1-5; LensEnforcement: 6 via
gate #55b separate dispatch). TimingPayload canonicalization (which
contradicted Director ratification) removed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(canvas): resolve option (c) Pro/Con contradiction on signature collision

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:137):
option (c) Pro line said 'avoids violates signature collision entirely'
but lines 135/139 routed back to (a)(ii)/(a)(iii) — internal
contradiction; fail-closed obligation under P3/C-8 still ambiguous.

Fixed: rewrote (c) Pro/Con honestly — Pro = state-space discipline
(per Director's ratification reasoning); Con = does NOT sidestep
violates signature collision, still requires substrate-extension
path. Status updated to reflect Director ratification at #828
c#4412301889: (c) carrier shape ratified for worker scope (#55a);
LensEnforcement substrate-extension disposition (#55b) still pending
between (a)(ii) and (a)(iii).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(v3): LensEnforcement.auto_violate_on_left for observation-driven lenses

Per Director ratification at gunb-ai/gunbc#828 c#4412884371 + re-confirmation
at c#4413159089: extend LensEnforcement<Output, Budget> with additive
auto_violate_on_left: Bool field for observation-driven lens classes
(T-Workflow-As-Data Slice 2 timing-lens et seq.).

Substrate semantics: when Output is Result-typed (e.g.,
Result<Observed, ObservationFailure> for timing), runtime checks the
bit before calling project; on Result-Left + bit=true, enforcement
violates without fabricating a Budget value at the projection
boundary. Preserves typed failure evidence (Missing/Ambiguous/Stale/
Unobserved) per INVARIANTS P3/C-8 fail-closed discipline.

Backward-compatible additive: existing structural-static lenses
(complexity, cost, T-LAS) set the bit to false; bit is inert when
Output is not Result-typed. Updated complexity_enforcement
declaration + hand-Rust LensEnforcement struct mirror.

Closes §1.8 ledger #55 sub-gate b (LensEnforcement substrate-extension
prerequisite for fail-closed-correct enforcement on non-Observed
report states); enables T-Workflow-As-Data Slice 2 worker
(tidy-raven-610 #2359) to revise PR #2360 against the ratified
Result-typed Output shape.

Canvas authority: docs/briefs/r3-substrate-t-wad-slice-2-timing-lens-canvas.md
§"Question 3 (Q-WAD-S2-Output)" + Gate #55 closure-predicate split.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Revert "feat(v3): LensEnforcement.auto_violate_on_left for observation-driven lenses"

This reverts commit 5ec59209d1c561788a4f6f686d8d1f62daf086ef.

* fix(canvas): Q-WAD-S2-Anchor recommendation aligned to Director ratification of (a)

Reviewer flagged BLOCKING on PR #2333 inline review (canvas:99): canvas
still recommended (b) generic anchor after Director ratified (a)
timing-specific. Competing WorkflowObservationAnchor authorities = P2
violation.

Fixed: Q-WAD-S2-Anchor recommendation rewritten to reflect Director
RATIFIED (a) per #828 c#4412301889 + c#4413322671. Mgr-tier preliminary
(b) was over-engineered (chased hypothetical second-consumer
parameterization). Invariant 5 split-authority concern resolved at
LensEnforcement layer per (a)(ii) full-signature extension (Director
c#4413284764) — violates pattern-matches Output variants directly,
no observation_outcome projection wrapper needed.

Co-Authored-By: Claude Opus 4.7 …
@briansrls briansrls mentioned this pull request May 11, 2026
briansrls added a commit that referenced this pull request May 14, 2026
Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request May 14, 2026
Follows the same convention as sibling
r3_free_consequences_second_batch_test::cross_target_optimization_cost_structurally_derived_receipt
(TESTING.md / lane2d note: heavy libtests stay listed until gate #102).

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request May 14, 2026
…ens-Composition) (#3087)

* WIP: R3 gate #38: coercion_cost_equals_complexity_by_construction (T-CostLens

* chore: apply cargo fmt for gate #38 receipt

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix: register gate #38 integration test in wall-clock warn manifest

Follows the same convention as sibling
r3_free_consequences_second_batch_test::cross_target_optimization_cost_structurally_derived_receipt
(TESTING.md / lane2d note: heavy libtests stay listed until gate #102).

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
@briansrls
briansrls deleted the auth-pattern-slice8 branch June 1, 2026 18:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant